Description
dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.
Remediation
References
Related Vulnerabilities
Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.42)
Squid Exposure of Resource to Wrong Sphere Vulnerability (CVE-2020-8449)
Internet Information Services Other Vulnerability (CVE-2001-0004)
WordPress Plugin Blogstand Banner Cross-Site Scripting (1.0)
ownCloud Improper Input Validation Vulnerability (CVE-2012-5336)