Description
SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.
Remediation
References
Related Vulnerabilities
WordPress Plugin Survey Maker-Best WordPress Survey SQL Injection (1.5.5)
MediaWiki Insertion of Sensitive Information into Log File Vulnerability (CVE-2024-40596)
MySQL CVE-2019-2730 Vulnerability (CVE-2019-2730)
Atlassian Confluence Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-29450)
Dolibarr Incorrect Authorization Vulnerability (CVE-2021-37517)