ZeroHour

CVE-2016-4040

CVSS 3.0
7.2 high
EPSS
1%p69
Published
()
Modified
Description

SQL injection vulnerability in the Workflow Screen in dotCMS before 3.3.2 allows remote administrators to execute arbitrary SQL commands via the orderby parameter.

Vendors
dotcms
Products
dotcms
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.