Dotclear Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-6446 - Vulnerability Database

Dotclear Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-6446

Medium
Reference: CVE-2017-6446
Title: Dotclear Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

XSS was discovered in Dotclear v2.11.2 affecting admin/blogs.php and admin/users.php with the sortby and order parameters.