Description
SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.
Remediation
References
Related Vulnerabilities
b2evolution Other Vulnerability (CVE-2007-2358)
Drupal Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2020-36193)
WordPress Plugin Download Manager PHAR Deserialization (3.2.49)
Joomla Improper Authentication Vulnerability (CVE-2022-23795)
MediaWiki Improper Input Validation Vulnerability (CVE-2011-1579)