Page 5 of 21 results (0.025 seconds)
CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1
CVE-2017-5876
https://notcve.org/view.php?id=CVE-2017-5876
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter. XSS fue descubierto en dotCMS 3.7.0, con un ataque no autenticado contra el parámetro /news-events/events date. • http://www.securityfocus.com/bid/96115 https://github.com/dotCMS/core/issues/10643 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •