Description
XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Lifeline Donation Security Bypass (1.2.6)
WordPress Plugin MF Gig Calendar Cross-Site Scripting (1.1)
WordPress Plugin Contact Form 7 Arbitrary File Upload (3.5.3)
MediaWiki Uncontrolled Resource Consumption Vulnerability (CVE-2022-39194)
WordPress Plugin WordPress Button Plugin MaxButtons Security Bypass (1.19.0)