Fortinet Discovers dotCMS XSS Filter Bypass Vulnerability
Summary
Fortinet's FortiGuard Labs had discovered XSS Filter Bypass vulnerability in dotCMS Core.
dotCMS is an open source content management system (CMS) written in Java for managing content and content driven sites and applications.
The
vulnerability is caused by broken authorization in dotCMS Core. Upon
successful exploitation, it allows attackers to launch client-side
script execution in the browser's process context.
Solutions
FortiGuard Labs released the following FortiGate IPS signature which covers this specific vulnerability:dotCMS.Core.XSSFilter.Bypass
Released Sep 08, 2022
Users should apply the solution provided by dotCMS.
Additional Information
The vulnerability affected dotCMS Core version 22.05 and below.
Timeline
Fortinet reported the vulnerability to dotCMS on 10th June, 2022.
dotCMS confirmed the vulnerability on 25th June, 2022.