Description
Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web script or HTML via the malicious user's email.
Remediation
References
Related Vulnerabilities
Play Framework Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-3630)
Jenkins Session Fixation Vulnerability (CVE-2021-21671)
Joomla Session Fixation Vulnerability (CVE-2010-1434)
SharePoint CVE-2020-1338 Vulnerability (CVE-2020-1338)
WordPress Plugin Front End Upload 'upload.php' Arbitrary File Upload (0.5.3)