Description
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Authorize.net Payment Gateway For WooCommerce Security Bypass (2.0)
Roundcube Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-4076)
MySQL CVE-2022-21304 Vulnerability (CVE-2022-21304)
WordPress Plugin GD Star Rating 'export.php' Security Bypass (1.9.18)
WordPress Plugin Custom Login Page Customizer-LoginPress Multiple Vulnerabilities (1.1.13)