MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in dotCMS before 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) _loginUserName parameter to application/login/login.html, (2) my_account_login parameter to c/portal_public/login, or (3) email parameter to forgotPassword
Published Apr 2, 2014
4.3
MEDIUMCVSS 2.0
EPSS 1.88%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.