Description
dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.
Remediation
References
Related Vulnerabilities
WordPress Plugin Cookie Notice & Compliance for GDPR/CCPA Cross-Site Scripting (2.1.1)
Oracle Database Server CVE-2019-2799 Vulnerability (CVE-2019-2799)
WordPress Plugin Google Drive for WordPress Arbitrary File Deletion (2.2)
PHP Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2023-0567)