CVE-2020-27848
HIGH WAF: High
CVSS 8.8
Published: 2020-12-30
CWE-89
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated manager in the dotCMS system to exploit this vulnerability.
WAF Coverage Analysis
SQL Injection
High WAF Coverage
OWASP: A03:2021 Injection
942xxx - SQL Injection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| dotcms | dotcms | up to 20.10.1 |
References
- github.com (Patch, Third Party Advisory)
- github.com (Exploit, Third Party Advisory)