VulnerabilityModified
CVE-2016-3688
SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.
MEDIUM 6.5EPSS 1.58%
Does this matter?
Lower severity and a low EPSS score (1.58%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.58% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- dotcms/dotcms
- Source
- cve@mitre.org
References
- http://dotcms.com/security/SI-32Vendor Advisory
- http://packetstormsecurity.com/files/136548/DotCMS-3.3-SQL-Injection.htmlExploit
- http://seclists.org/fulldisclosure/2016/Apr/11
- http://seclists.org/fulldisclosure/2016/Apr/5
- http://dotcms.com/security/SI-32Vendor Advisory
- http://packetstormsecurity.com/files/136548/DotCMS-3.3-SQL-Injection.htmlExploit
- http://seclists.org/fulldisclosure/2016/Apr/11
- http://seclists.org/fulldisclosure/2016/Apr/5
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.