Description
A stored cross site scripting (XSS) vulnerability in dotAdmin/#/c/c_Images of dotCMS 21.05.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' and 'Filename' parameters.
Remediation
References
Related Vulnerabilities
Drupal Core 9.2.x Multiple Vulnerabilities (9.2.0 - 9.2.14)
Grafana CVE-2022-39307 Vulnerability (CVE-2022-39307)
WordPress Plugin dsIDXpress IDX Multiple Unspecified Vulnerabilities (2.1.32)
Drupal Improper Authentication Vulnerability (CVE-2010-3091)
Oracle Application Server Other Vulnerability (CVE-2007-0283)