Lucene search

K
cvelistMitreCVELIST:CVE-2020-27848
HistoryDec 30, 2020 - 6:24 p.m.

CVE-2020-27848

2020-12-3018:24:20
mitre
www.cve.org

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.4%

dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated manager in the dotCMS system to exploit this vulnerability.

8.9 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

45.4%

Related for CVELIST:CVE-2020-27848