Description
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin MegaOptim Image Optimizer Unspecified Vulnerability (1.3.2)
MediaWiki Other Vulnerability (CVE-2023-37300)
WordPress Plugin Easy Forms for Mailchimp Unspecified Vulnerability (6.6.2)
Jboss EAP Other Vulnerability (CVE-2010-4265)
WordPress Plugin bbPress Move Topics PHP Object Injection (1.1.4)