Description
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Activity Log Information Disclosure (2.2.12)
Apache Traffic Server Improper Authentication Vulnerability (CVE-2021-44759)
Oracle JRE CVE-2012-0504 Vulnerability (CVE-2012-0504)
phpMyAdmin Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-1000499)
PmWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4453)