Description
An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp.
Remediation
References
Related Vulnerabilities
WordPress Plugin ALO EasyMail Newsletter Multiple Vulnerabilities (2.6.00)
WordPress Plugin uCare-Support Ticket System Cross-Site Scripting (1.2.1)
WordPress Plugin Relevanssi Premium-A Better Search Multiple Vulnerabilities (1.14.4)
Liferay DXP Improper Certificate Validation Vulnerability (CVE-2022-42131)