Lucene search

K
osvGoogleOSV:CVE-2020-27848
HistoryDec 30, 2020 - 7:15 p.m.

CVE-2020-27848

2020-12-3019:15:13
Google
osv.dev
8
dotcms
sql injection
orderby parameter
paginatorordered classes
rest endpoints
authentication
vulnerability

AI Score

7.8

Confidence

Low

EPSS

0.001

Percentile

45.2%

dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated manager in the dotCMS system to exploit this vulnerability.

AI Score

7.8

Confidence

Low

EPSS

0.001

Percentile

45.2%

Related for OSV:CVE-2020-27848