Dot CMS Permissions Privileges and Access Controls Vulnerability - CVE-2012-1826 - Vulnerability Database

Dot CMS Permissions Privileges and Access Controls Vulnerability - CVE-2012-1826

Medium
Reference: CVE-2012-1826
Title: Dot CMS Permissions Privileges and Access Controls Vulnerability
Overview:

dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.