5
CVSSv2

CVE-2016-4803

Published: 30/06/2016 Updated: 28/11/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in the send email functionality in dotCMS prior to 3.3.2 allows remote malicious users to inject arbitrary email headers via CRLF sequences in the subject.

Vulnerable Product Search on Vulmon Subscribe to Product

dotcms dotcms

Exploits

dotCMS versions prior to 35 and 332 suffers from an email header injection vulnerability ...