Dot CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-5876
XSS was discovered in dotCMS 3.7.0 with an unauthenticated attack against the /news-events/events date parameter.
XSS was discovered in dotCMS 3.7.0 with an unauthenticated attack against the /news-events/events date parameter.