Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

P0X2015

#40735of 53,625
6.5Total CVSS
Vulnerabilities · 1
PT-2016-5660
6.5
2016-04-19
Dotcms · Dotcms · CVE-2016-3688
**Name of the Vulnerable Software and Affected Versions** dotCMS versions prior to 3.5 **Description** The issue allows remote administrators to execute arbitrary SQL commands. This is achieved via the "c0-e3" parameter to the "/dwr/call/plaincall/UserAjax.getUsersList.dwr" API endpoint, specifically by exploiting the `c0-e3` parameter. **Recommendations** For versions prior to 3.5, update to version 3.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/dwr/call/plaincall/UserAjax.getUsersList.dwr" API endpoint to minimize the risk of exploitation. Avoid using the `c0-e3` parameter in the affected API endpoint until the issue is resolved.