CVE-2018-17422: dotCMS
Medium severity, CVSS 6.1. EPSS: 3.7% chance of exploitation in the next 30 days.
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
Affected products
- dotCMS dotCMS: before 5.0.2 (fixed in 5.0.2)
Published 2019-03-07. Last modified 2026-06-17.