CVE-2024-3938: dotCMS
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a http://localhost:8082/dotAdmin/#/public/login?resetEmailSent=true&resetEmail=%3Ch1%3E%3Ca%20href%3D%22https:%2F%2Fgoogle.com%22%3ECLICK%20ME%3C%2Fa%3E%3C%2Fh1%3E This will result in a view along these lines: * OWASP Top 10 - A03: Injection * CVSS Score: 5.4 * AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator * https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&... https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
Affected products
- dotCMS dotCMS: from 5.1.5, before 23.01.18 (fixed in 23.01.18); from 23.02, up to and including 23.09.7; from 23.12.21, up to and including 24.04.23; from 24.05.13, before 24.05.31 (fixed in 24.05.31); version 23.10.24 only; version 23.10.24.0 only; …
Published 2024-07-25. Last modified 2026-06-17.