CVE-2016-8907

8.8HIGH

SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

Veröffentlicht: 11/14/2016Aktualisiert: 4/12/2025

Beschreibung

SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

KI-AnalyseKI-gestützt

Betroffene Produkte

dotcmsdotcms

Referenzen