Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Wezell

#21340of 53,632
11.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2016-5816
7.2
2016-04-19
Dotcms · Dotcms · CVE-2016-4040
**Name of the Vulnerable Software and Affected Versions** dotCMS versions prior to 3.3.2 **Description** The issue allows remote administrators to execute arbitrary SQL commands. This is achieved via the `orderby` parameter in the Workflow Screen. **Recommendations** For versions prior to 3.3.2, update to version 3.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Workflow Screen or avoiding the use of the `orderby` parameter until the update is applied.
PT-2014-2684
4.3
2014-04-02
Dotcms · Dotcms · CVE-2013-3484
**Name of the Vulnerable Software and Affected Versions** dotCMS versions prior to 2.3.2 **Description** The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the ` loginUserName` parameter to the "application/login/login.html" endpoint, the `my account login` parameter to the "c/portal public/login" endpoint, or the `email` parameter to the "forgotPassword" endpoint. **Recommendations** For versions prior to 2.3.2, update to version 2.3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable endpoints until a patch is applied. Avoid using the ` loginUserName`, `my account login`, and `email` parameters in the affected endpoints until the issue is resolved.