VYPR

Dotcms

by Dotcms

Source repositories

CVEs (61)

  • CVE-2017-3189HigJul 24, 2018
    risk 0.53cvss 8.1epss 0.07

    The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, there are no checks on the types of files…

  • CVE-2016-8600HigOct 28, 2016
    risk 0.49cvss 7.5epss 0.02

    In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.

  • CVE-2016-4803HigJun 30, 2016
    risk 0.49cvss 7.5epss 0.02

    CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject.

  • CVE-2019-12872HigJun 18, 2019
    risk 0.47cvss 7.2epss 0.01

    dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp.

  • CVE-2017-11466HigJul 20, 2017
    risk 0.47cvss 7.2epss 0.08

    Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName parameter to…

  • CVE-2016-4040HigApr 19, 2016
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter.

  • CVE-2022-45783MedFeb 1, 2023
    risk 0.43cvss 6.5epss 0.08

    An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the dotCMS API can lead to Remote Code Execution.

  • CVE-2022-37033MedFeb 1, 2023
    risk 0.42cvss 6.5epss 0.01

    In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to block any SSRF access to local IP addresses or private subnets. In resolving this URL, the TempFileAPI follows any 302 redirects that the remote URL returns.…

  • CVE-2017-3188MedJul 24, 2018
    risk 0.42cvss 6.5epss 0.03

    The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, the filenames of its contents are not properly…

  • CVE-2016-3688MedApr 19, 2016
    risk 0.42cvss 6.5epss 0.02

    SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.

  • CVE-2022-35740MedNov 10, 2022
    risk 0.40cvss 6.1epss 0.01

    dotCMS before 22.06 allows remote attackers to bypass intended access control and obtain sensitive information by using a semicolon in a URL to introduce a matrix parameter. (This is also fixed in 5.3.8.12, 21.06.9, and 22.03.2 for LTS users.) Some Java application frameworks,…

  • CVE-2022-37431MedAug 5, 2022
    risk 0.40cvss 6.1epss 0.01

    A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin portal when the configuration has XSS_PROTECTION_ENABLED=false. NOTE: the vendor disputes this because the current product behavior, in effect, has…

  • CVE-2019-11846MedMay 14, 2019
    risk 0.40cvss 6.1epss 0.01

    /servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.

  • CVE-2018-17422MedMar 7, 2019
    risk 0.40cvss 6.1epss 0.04

    dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.

  • CVE-2018-16980MedSep 12, 2018
    risk 0.40cvss 6.1epss 0.01

    dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.

  • CVE-2016-10008HigFeb 19, 2018
    risk 0.40cvss 7.2epss 0.01

    SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.

  • CVE-2016-10007HigFeb 19, 2018
    risk 0.40cvss 7.2epss 0.01

    SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.

  • CVE-2017-6003MedMar 27, 2017
    risk 0.40cvss 6.1epss 0.01

    dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.

  • CVE-2017-5877MedFeb 6, 2017
    risk 0.40cvss 6.1epss 0.01

    XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.

  • CVE-2017-5876MedFeb 6, 2017
    risk 0.40cvss 6.1epss 0.01

    XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.