VDB

GCVE-110-CERTCC-2017-168699

GCVE-110-CERTCC-2017-168699
Advisory PublishedCVSS 6.8/10
Vulnetix · Advisory published March 6, 2017
The dotCMS administration panel is vulnerable to cross-site request forgery, and the "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal and arbitrary file upload. dotCMS versions 3.7.1 and earlier are affected.

Risk Scores

CVSS 2.0
6.8/10
Medium · AV:N/AC:M/Au:N/C:P/I:P/A:P
certcc-cam
certcc-cam
impact0population0exploitation0widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_impact2d1_population2d1_direct_report1
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score6.1remediation_levelUreport_confidenceCenvironmental_score4.60507672760625target_distributionMenvironmental_vectorCDP:ND/TD:M/CR:ND/IR:ND/AR:ND

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›