Description
SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.
Remediation
References
Related Vulnerabilities
WeBid Incorrect Comparison Vulnerability (CVE-2020-23359)
WordPress Plugin WP-Filebase Download Manager Cross-Site Scripting (3.1.02)
WordPress Plugin Downloads Manager 'upload.php' Arbitrary File Upload (0.2)
Atlassian Confluence Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-22504)
WordPress Incorrect Authorization Vulnerability (CVE-2017-6816)