Description
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
Remediation
References
Related Vulnerabilities
Drupal Core Security Bypass (8.0.0 - 9.2.21)
WordPress Plugin Affiliate Press Multiple Cross-Site Scripting Vulnerabilities (0.3.8)
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-41892)
MySQL Improper Validation of Array Index Vulnerability (CVE-2022-21310)