SQL Injection Vulnerability in dotCMS Product by dotCMS
CVE-2016-10007
7.2HIGH
What is CVE-2016-10007?
An SQL injection vulnerability exists in the administrative interface of dotCMS prior to version 3.7.2 and 4.x versions before 4.1.1. This flaw allows remote authenticated administrators to execute arbitrary SQL commands by manipulating the _EXT_FORM_HANDLER_orderBy parameter. Exploiting this vulnerability could lead to unauthorized access and data compromise.
