SQL Injection Vulnerability in dotCMS by dotCMS
CVE-2017-5344
What is CVE-2017-5344?
An SQL Injection vulnerability exists in dotCMS versions up to 3.6.1 via the /categoriesServlet path. This issue arises from the findChildrenByFilter() function, which allows for string interpolation and direct execution of SQL queries. Although mitigation measures like SQL quote escaping and a keyword blacklist were introduced to address prior vulnerabilities, these protections can be bypassed through specific parameters (q and inode). This oversight allows attackers to exploit the /categoriesServlet remotely, without authentication, potentially leading to exposure of sensitive information through various blind boolean SQL injection techniques.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
