SQL Injection Vulnerability in dotCMS by dotCMS
CVE-2016-8906
8.8HIGH
What is CVE-2016-8906?
A vulnerability exists in the 'Site Browser > Links pages' screen of dotCMS prior to version 3.3.1, where remote authenticated attackers can leverage the orderby parameter to execute arbitrary SQL commands. This flaw poses a significant risk as it can lead to unauthorized access and manipulation of database information.
