Description
/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.
Remediation
References
Related Vulnerabilities
WordPress Plugin BackWPup Cross-Site Scripting (3.2.3)
Oracle JRE CVE-2014-0464 Vulnerability (CVE-2014-0464)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-14642)
MySQL CVE-2020-14614 Vulnerability (CVE-2020-14614)
WordPress Plugin WP Photo Album Plus Cross-Site Scripting (5.0.10)