Description
SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
Remediation
References
Related Vulnerabilities
Apache Tomcat Incomplete Cleanup Vulnerability (CVE-2023-42795)
WordPress Plugin 10Web AI Assistant-AI content writing assistant Security Bypass (1.0.18)
SharePoint CVE-2022-21987 Vulnerability (CVE-2022-21987)
WordPress Plugin Advanced Custom Fields (ACF) Arbitrary File Upload (5.12.2)
WordPress Plugin WP e-Commerce Predictive Search Cross-Site Scripting (1.1.1)