Description
dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2011-3182)
Moodle URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-14830)
WeBid Other Vulnerability (CVE-2014-5114)
Jetty Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2021-28163)
WordPress Plugin Contact Form 7 Style Cross-Site Request Forgery (3.1.9)