QID 150741
Date Published: 2023-11-14
QID 150741: dotCMS Broken Access Control Vulnerability (CVE-2023-3042)
dotCMS is an open source content management system written in Java for managing content and content driven sites and applications.
In dotCMS, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs potentially enabling bypasses for XSS and access controls.
Affected versions:
dotCMS versions from 5.3.8, 21.06, 22.03 and 23.01
QID Detection Logic (Unauthenticated):
This QID performs a HTTP GET request to the "/api/v1/appconfiguration" endpoint and examines the response body to determine if the host is running a vulnerable version of the dotCMS Server.
Successful exploitation of the vulnerability can allow an attacker to trigger a XSS and access controls.
Solution
Customers are recommended to upgrade to the latest version of dotCMS to remediate this vulnerability. For further details regarding this issue, please refer to SI-68.
Vendor References
- SI-68 -
www.dotcms.com/security/SI-68
CVEs related to QID 150741
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SI-68 |
|