6.5
CVSSv2

CVE-2016-8905

Published: 14/11/2016 Updated: 29/11/2016
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the JSONTags servlet in dotCMS prior to 3.3.1 allows remote authenticated malicious users to execute arbitrary SQL commands via the sort parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dotcms dotcms

Exploits

dotCMS versions before 35, 331, and 332 suffer from multiple remote SQL injection vulnerabilities ...