Description
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2018-3197 Vulnerability (CVE-2018-3197)
WordPress Plugin Bulk Add to Cart for WooCommerce Security Bypass (1.2.2)
WordPress Plugin Social Media Widget Serving Spam (4.0)
Nginx Out-of-bounds Read Vulnerability (CVE-2023-27728)
WordPress Plugin uContext for Amazon Cross-Site Request Forgery (3.9.1)