SQL Injection in DotCMS Before 3.3.1
CVE-2016-8903
8.8HIGH
What is CVE-2016-8903?
A SQL injection vulnerability exists in the 'Site Browser > Templates pages' screen of dotCMS prior to version 3.3.1, where a remote authenticated attacker can exploit the 'orderby' parameter to execute arbitrary SQL commands. This presents a significant risk as it could lead to unauthorized access to sensitive data or manipulation of the database. Proper input validation is essential to mitigate the risk associated with this vulnerability.
