Description
XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.
Remediation
References
Related Vulnerabilities
SugarCRM Other Vulnerability (CVE-2009-2146)
PHP Out-of-bounds Read Vulnerability (CVE-2017-9118)
WordPress Plugin Crowd Ideas Cross-Site Scripting (1.0)
Oracle Database Server CVE-2010-0870 Vulnerability (CVE-2010-0870)
WordPress Plugin AVH Extended Categories Widgets Unspecified Vulnerability (4.0.2)