Fortinet Discovers dotCMS Multiple Cross-Site Scripting Vulnerability
Summary
Fortinet's FortiGuard Labs had discovered multiple Cross-Site Scripting (XSS) vulnerabilities in dotCMS Admin Portal.
dotCMS is an open source content management system (CMS) written in Java for managing content and content driven sites and applications.
These vulnerabilities are caused by insufficient input sanitization in dotCMS Core. Upon
successful exploitation, it allows attackers to launch client-side
script execution in the browser's process context.
Solutions
FortiGuard Labs released the following FortiGate IPS signature which covers this specific vulnerability:dotCMS.Portal.Multiple.XSS
Released Aug 02, 2022
Users should always enable XSS Prevention feature on dotCMS.
Additional Information
The vulnerability affected dotCMS Core.
Timeline
Fortinet reported the vulnerability to dotCMS on 10th June, 2022.
dotCMS confirmed the vulnerability on 25th June, 2022 and concluded it as a no-fix issue.Â