VDB
GCVE-110-CERTCC-2017-168699
GCVE-110-CERTCC-2017-168699
Advisory PublishedCVSS 6.8/10
The dotCMS administration panel is vulnerable to cross-site request forgery, and the "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal and arbitrary file upload. dotCMS versions 3.7.1 and earlier are affected.
Risk Scores
CVSS 2.0
6.8/10
Medium · AV:N/AC:M/Au:N/C:P/I:P/A:P
certcc-cam
certcc-cam
impact0population0exploitation0widely_known0score_current0ease_of_exploitation0
certcc-vrda
certcc-vrda
d1_impact2d1_population2d1_direct_report1
certcc-cvss-temporal-env
certcc-cvss-temporal-env
temporal_score6.1remediation_levelUreport_confidenceCenvironmental_score4.60507672760625target_distributionMenvironmental_vectorCDP:ND/TD:M/CR:ND/IR:ND/AR:ND
Browse GCVE Records
73,877 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.