Dotcms · Dotcms · CVE-2016-3688
**Name of the Vulnerable Software and Affected Versions**
dotCMS versions prior to 3.5
**Description**
The issue allows remote administrators to execute arbitrary SQL commands. This is achieved via the "c0-e3" parameter to the "/dwr/call/plaincall/UserAjax.getUsersList.dwr" API endpoint, specifically by exploiting the `c0-e3` parameter.
**Recommendations**
For versions prior to 3.5, update to version 3.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/dwr/call/plaincall/UserAjax.getUsersList.dwr" API endpoint to minimize the risk of exploitation. Avoid using the `c0-e3` parameter in the affected API endpoint until the issue is resolved.