Description
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2009-1965 Vulnerability (CVE-2009-1965)
MySQL CVE-2016-7440 Vulnerability (CVE-2016-7440)
WordPress Plugin WP CSS 'wp-css-compress.php' Local File Disclosure (2.0.5)
WordPress Plugin WP STAGING WordPress Backup-Migration Backup Restore Arbitrary File Upload (3.4.3)
WordPress Ultimate Member Plugin CVE-2019-10271 Vulnerability (CVE-2019-10271)