Description
SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.
Remediation
References
Related Vulnerabilities
IBM WebSEAL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1805)
PHP Improper Input Validation Vulnerability (CVE-2008-3660)
WordPress Plugin Bulk Delete Users by Email Cross-Site Request Forgery (1.0)
OpenSSL Integer Overflow or Wraparound Vulnerability (CVE-2021-23840)