Description
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
Remediation
References
Related Vulnerabilities
Plone CMS Resource Management Errors Vulnerability (CVE-2013-4188)
WordPress Plugin Genie WP Favicon Cross-Site Request Forgery (0.5.2)
WordPress Plugin WP SimpleMail Multiple Cross-Site Scripting Vulnerabilities (1.0.6)
WordPress Plugin GTM4WP Cross-Site Scripting (1.9)
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2024-25605)