ZeroHour

CVE-2020-18875

CVSS 3.1
8.8 high
EPSS
2%p79
Published
()
Modified
Description

Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.

Vendors
dotcms
Products
dotcms
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.