Description
SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-3645 Vulnerability (CVE-2017-3645)
Squid Missing Release of Resource after Effective Lifetime Vulnerability (CVE-2018-19132)
WordPress Plugin wpShopGermany Free Arbitrary File Upload (4.0.10)
Drupal Core 7.x Multiple Vulnerabilities (7.0 - 7.23)
WordPress Plugin Social Auto Poster-WordPress Scheduler & Marketing Arbitrary File Upload (5.3.14)