CVE-2024-3938

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
25/07/2024
Last modified:
13/08/2024

Description

The "reset password" login page accepted an HTML injection via URL parameters.<br /> <br /> This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a http://localhost:8082/dotAdmin/#/public/login?resetEmailSent=true&amp;resetEmail=%3Ch1%3E%3Ca%20href%3D%22https:%2F%2Fgoogle.com%22%3ECLICK%20ME%3C%2Fa%3E%3C%2Fh1%3E <br /> <br /> This will result in a view along these lines:<br /> <br /> <br /> <br /> <br /> <br /> * OWASP Top 10 - A03: Injection<br /> * CVSS Score: 5.4<br /> * AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator <br /> * https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&amp;... https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* 5.1.5 (including) 23.01.18 (excluding)
cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* 23.02 (including) 23.09.7 (including)
cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* 23.12.21 (including) 24.04.23 (including)
cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* 24.05.13 (including) 24.05.31 (excluding)
cpe:2.3:a:dotcms:dotcms:23.10.24:1:*:*:lts:*:*:*
cpe:2.3:a:dotcms:dotcms:23.10.24:10:*:*:lts:*:*:*
cpe:2.3:a:dotcms:dotcms:23.10.24:2:*:*:lts:*:*:*
cpe:2.3:a:dotcms:dotcms:23.10.24:3:*:*:lts:*:*:*
cpe:2.3:a:dotcms:dotcms:23.10.24:4:*:*:lts:*:*:*
cpe:2.3:a:dotcms:dotcms:23.10.24:5:*:*:lts:*:*:*
cpe:2.3:a:dotcms:dotcms:23.10.24:6:*:*:lts:*:*:*
cpe:2.3:a:dotcms:dotcms:23.10.24:7:*:*:lts:*:*:*
cpe:2.3:a:dotcms:dotcms:23.10.24:8:*:*:lts:*:*:*
cpe:2.3:a:dotcms:dotcms:23.10.24:9:*:*:lts:*:*:*
cpe:2.3:a:dotcms:dotcms:23.10.24.0:*:*:*:lts:*:*:*


References to Advisories, Solutions, and Tools