Dot CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-11846 - Vulnerability Database

Dot CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-11846

Medium
Reference: CVE-2019-11846
Title: Dot CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

/servlets/ajax_file_uploadfieldNamebinary3 in dotCMS 5.1.1 allows XSS and HTML Injection.