Description
A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin portal when the configuration has XSS_PROTECTION_ENABLED=false. NOTE: the vendor disputes this because the current product behavior, in effect, has XSS_PROTECTION_ENABLED=true in all configurations
Remediation
References
Related Vulnerabilities
Apache HTTP Server Other Vulnerability (CVE-2013-4352)
WordPress Plugin afterRead Unspecified Vulnerability (0.3)
XWiki Missing Authorization Vulnerability (CVE-2022-41930)
WordPress Plugin WP Selected Text Sharer Multiple Vulnerabilities (1.0)
MySQL Resource Management Errors Vulnerability (CVE-2010-3677)