| Issue: |
|
||
|---|---|---|---|
| Date: |
|
||
| Severity: | Medium | ||
| Requires Admin Access: | Yes | ||
| Fix Version: | 1.9.5.1 | ||
| Credit: | Cert.org / Ben Murphy | ||
| Description: |
OverviewThe dotCMS content management system version 1.9 and possibly earlier versions, contains a vulnerability that allows users with admin access the appropriate permissions to create a malicious template with arbitrary code. An authenticated dotCMS user with the permissions required to author and upload templates may create a malicious XSLT or Velocity template that can execute arbitrary java code. The arbitrary java code will run with the permissions of the web service account. Impact
|
||
| Mitigation: |
|
||
| References |
|