Description
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce PDF Invoice and Shipping List Security Bypass (1.2.12)
Atlassian Jira Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2021-41306)
WordPress Plugin Responsive Poll Multiple Vulnerabilities (1.7.4)
SharePoint Improper Input Validation Vulnerability (CVE-2019-0594)