Reflected Cross Site Scripting Vulnerability in dotCMS by dotCMS
CVE-2021-35360
4.8MEDIUM
What is CVE-2021-35360?
A reflected cross site scripting (XSS) vulnerability exists in dotCMS version 21.05.1, specifically within the dotAdmin interface at the /#/c/containers endpoint. This flaw allows attackers to execute arbitrary HTML or JavaScript commands through specially crafted payloads, potentially compromising the security of affected installations and exposing user data.
