CVE-2024-3938
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
25/07/2024
Last modified:
13/08/2024
Description
The "reset password" login page accepted an HTML injection via URL parameters.<br />
<br />
This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a http://localhost:8082/dotAdmin/#/public/login?resetEmailSent=true&resetEmail=%3Ch1%3E%3Ca%20href%3D%22https:%2F%2Fgoogle.com%22%3ECLICK%20ME%3C%2Fa%3E%3C%2Fh1%3E <br />
<br />
This will result in a view along these lines:<br />
<br />
<br />
<br />
<br />
<br />
* OWASP Top 10 - A03: Injection<br />
* CVSS Score: 5.4<br />
* AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator <br />
* https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&... https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* | 5.1.5 (including) | 23.01.18 (excluding) |
| cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* | 23.02 (including) | 23.09.7 (including) |
| cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* | 23.12.21 (including) | 24.04.23 (including) |
| cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* | 24.05.13 (including) | 24.05.31 (excluding) |
| cpe:2.3:a:dotcms:dotcms:23.10.24:1:*:*:lts:*:*:* | ||
| cpe:2.3:a:dotcms:dotcms:23.10.24:10:*:*:lts:*:*:* | ||
| cpe:2.3:a:dotcms:dotcms:23.10.24:2:*:*:lts:*:*:* | ||
| cpe:2.3:a:dotcms:dotcms:23.10.24:3:*:*:lts:*:*:* | ||
| cpe:2.3:a:dotcms:dotcms:23.10.24:4:*:*:lts:*:*:* | ||
| cpe:2.3:a:dotcms:dotcms:23.10.24:5:*:*:lts:*:*:* | ||
| cpe:2.3:a:dotcms:dotcms:23.10.24:6:*:*:lts:*:*:* | ||
| cpe:2.3:a:dotcms:dotcms:23.10.24:7:*:*:lts:*:*:* | ||
| cpe:2.3:a:dotcms:dotcms:23.10.24:8:*:*:lts:*:*:* | ||
| cpe:2.3:a:dotcms:dotcms:23.10.24:9:*:*:lts:*:*:* | ||
| cpe:2.3:a:dotcms:dotcms:23.10.24.0:*:*:*:lts:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



