{"vars":{{"pagePostType":"post","pagePostType2":"single-post","pageCategory":["advisory","hacked-website-repair","security","vulnerability","webapp","website-malware-removal"],"pagePostAuthor":"Secureli Support"}} }

dotCMS v5.1.1 HTML Injection & XSS Vulnerability

dotCMS v5.1.1 suffers from an HTML injection and XSS vulnerability, in addition to many other vulnerabilities that I am still verifying.

Here’s a screenshot of HTML injection:

To reproduce this vulnerability, simply go to https://dotcms.com/dotAdmin/ and login with their demo credentials (username: admin@dotcms.com password: admin) and then visit the following URL:


There are more unconfirmed vulnerabilities in dotCMS.

Exit mobile version