Description
A stored cross site scripting (XSS) vulnerability in dotAdmin/#/c/c_Images of dotCMS 21.05.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' and 'Filename' parameters.
Remediation
References
Related Vulnerabilities
Joomla Other Vulnerability (CVE-2007-0374)
MySQL CVE-2012-3149 Vulnerability (CVE-2012-3149)
phpMyAdmin Improper Input Validation Vulnerability (CVE-2011-3646)
Python Untrusted Search Path Vulnerability (CVE-2008-5983)
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-15929)