Dot CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-5877 - Vulnerability Database

Dot CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-5877

Medium
Reference: CVE-2017-5877
Title: Dot CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

XSS was discovered in dotCMS 3.7.0 with an unauthenticated attack against the /about-us/locations/index direction parameter.