Description
Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Fancy Product Designer-WooCommerce Cross-Site Scripting (3.4.1)
WordPress Plugin All-in-One Event Calendar Multiple Vulnerabilities (1.9)
MediaWiki Improper Access Control Vulnerability (CVE-2016-6337)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2022-31780)
WordPress Plugin Caldera Forms-More Than Contact Forms Cross-Site Scripting (1.4.1)