Issue: |
|
||
---|---|---|---|
Date: |
|
||
Severity: | Medium | ||
Requires Admin Access: | Yes | ||
Fix Version: | 1.9.5.1 | ||
Credit: | Cert.org / Ben Murphy | ||
Description: |
OverviewThe dotCMS content management system version 1.9 and possibly earlier versions, contains a vulnerability that allows users with admin access the appropriate permissions to create a malicious template with arbitrary code. An authenticated dotCMS user with the permissions required to author and upload templates may create a malicious XSLT or Velocity template that can execute arbitrary java code. The arbitrary java code will run with the permissions of the web service account. Impact
|
||
Mitigation: |
|
||
References |
|