Description
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Questions and Answers Security Bypass (1.1.9)
Microsoft SQL Server Other Vulnerability (CVE-2000-0654)
Play Framework Inadequate Encryption Strength Vulnerability (CVE-2019-17598)
Envoy Proxy Use After Free Vulnerability (CVE-2023-35942)
WordPress Plugin Post to CSV by BestWebSoft Cross-Site Scripting (1.3.0)