QID 150580
Date Published: 2022-10-12
QID 150580: dotCMS Cross-Site Scripting (XSS) Vulnerability (CVE-2022-35740)
dotCMS is an open source content management system written in Java for managing content and content driven sites and applications.
On affected versions of dotCMS core a XSS Filter Bypass vulnerability exists due to broken authorization which allows attackers to bypass XSSPreventionWebInterceptor using Matrix Parameter and exploit XSS vulnerability.
Affected versions:
dotCMS versions: 22.05 and below
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to "/api/v1/appconfiguration" endpoint and checks the response body to confirm if the host is running vulnerable version of dotCMS Server.
Successful exploitation could allow an attacker to execute arbitrary JavaScript code in the context of the interface or allow the attacker to access sensitive, browser-based information.
- CVE-2022-35740 -
www.fortiguard.com/zeroday/FG-VD-22-063
CVEs related to QID 150580
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-35740 |
|