Description
An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp.
Remediation
References
Related Vulnerabilities
WordPress Plugin AdSense Manager Cross-Site Scripting (4.0.3)
SugarCRM Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-35808)
WordPress Plugin Register IPs Unspecified Vulnerability (1.8.0)
WordPress Plugin WP-Polls Cross-Site Scripting (2.69)
WordPress Plugin MAC PHOTO GALLERY Multiple Security Bypass Vulnerabilities (3.0)