ZeroHour

CVE-2016-4803

PoC ×2
CVSS 3.0
7.5 high
EPSS
2%p82
Published
()
Modified
Description

CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject.

Vendors
dotcms
Products
dotcms
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.