vendor:
dotCMS
by:
Ismail Tasdelen
6.1
CVSS
MEDIUM
Code Injection
79
CWE
Product Name: dotCMS
Affected Version From: 5.1.1
Affected Version To: 5.1.1
Patch Exists: YES
Related CWE: CVE-2019-11846
CPE: a:dotcms:dotcms:5.1.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
dotCMS 5.1.1 – HTML Injection
A vulnerability in dotCMS 5.1.1 allows an attacker to inject malicious HTML and JavaScript code into the application. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. The vulnerability is due to insufficient validation of user-supplied input when uploading files. An attacker can exploit this vulnerability by sending a specially crafted HTTP POST request with malicious HTML code in the filename parameter.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to upgrade to the latest version of dotCMS.