Description
XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Modern Events Calendar Lite Cross-Site Scripting (5.22.2)
WordPress 5.2.x Multiple Vulnerabilities (5.2 - 5.2.19)
Claroline Other Vulnerability (CVE-2006-7048)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-5471)
WordPress Plugin Premmerce Wholesale Pricing for WooCommerce Security Bypass (1.1.3)