Description
An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp.
Remediation
References
Related Vulnerabilities
WordPress Plugin Carousel slideshow 'swfupload.swf' Cross-Site Scripting (3.10)
WebLogic CVE-2022-21441 Vulnerability (CVE-2022-21441)
Vanilla Forums Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2018-15833)
Apache Tomcat Other Vulnerability (CVE-2011-1088)
WordPress Plugin Quick Page/Post Redirect Open Redirect (5.1.5)