Description
Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component.
Remediation
References
Related Vulnerabilities
Joomla Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2006-4471)
MySQL CVE-2019-2960 Vulnerability (CVE-2019-2960)
WordPress Plugin WooCommerce Cross-Site Scripting (3.4.5)
ownCloud Other Vulnerability (CVE-2014-2053)
WordPress Plugin EZP Coming Soon Page Cross-Site Scripting (1.0.0)