CVE-2024-3938

Source
https://cve.org/CVERecord?id=CVE-2024-3938
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3938.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-3938
Published
2024-07-25T21:17:49.359Z
Modified
2026-07-15T02:11:58.732126413Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The "reset password" login page accepted an HTML injection via URL parameters.

This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a http://localhost:8082/dotAdmin/#/public/login?resetEmailSent=true&resetEmail=%3Ch1%3E%3Ca%20href%3D%22https:%2F%2Fgoogle.com%22%3ECLICK%20ME%3C%2Fa%3E%3C%2Fh1%3E

This will result in a view along these lines:

  • OWASP Top 10 - A03: Injection
  • CVSS Score: 5.4
  • AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
  • https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&... https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator
Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.1.5 and after"
                },
                {
                    "last_affected": "5.1.5 and after"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-20"
    ],
    "cna_assigner": "dotCMS",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/3xxx/CVE-2024-3938.json"
}
References

Affected packages

Git / github.com/dotcms/core

Affected ranges

Type
GIT
Repo
https://github.com/dotcms/core
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "5.1.5"
        },
        {
            "fixed": "23.01.18"
        },
        {
            "introduced": "23.02"
        },
        {
            "last_affected": "23.09.7"
        },
        {
            "introduced": "23.12.21"
        },
        {
            "last_affected": "24.04.23"
        },
        {
            "introduced": "24.05.13"
        },
        {
            "fixed": "24.05.31"
        },
        {
            "introduced": "23.10.24-1"
        },
        {
            "last_affected": "23.10.24-1"
        },
        {
            "introduced": "23.10.24-10"
        },
        {
            "last_affected": "23.10.24-10"
        },
        {
            "introduced": "23.10.24-2"
        },
        {
            "last_affected": "23.10.24-2"
        },
        {
            "introduced": "23.10.24-3"
        },
        {
            "last_affected": "23.10.24-3"
        },
        {
            "introduced": "23.10.24-4"
        },
        {
            "last_affected": "23.10.24-4"
        },
        {
            "introduced": "23.10.24-5"
        },
        {
            "last_affected": "23.10.24-5"
        },
        {
            "introduced": "23.10.24-6"
        },
        {
            "last_affected": "23.10.24-6"
        },
        {
            "introduced": "23.10.24-7"
        },
        {
            "last_affected": "23.10.24-7"
        },
        {
            "introduced": "23.10.24-8"
        },
        {
            "last_affected": "23.10.24-8"
        },
        {
            "introduced": "23.10.24-9"
        },
        {
            "last_affected": "23.10.24-9"
        },
        {
            "introduced": "23.10.24.0"
        },
        {
            "last_affected": "23.10.24.0"
        },
        {
            "introduced": "24.04.24-NA"
        },
        {
            "last_affected": "24.04.24-NA"
        },
        {
            "introduced": "24.04.24-0"
        },
        {
            "last_affected": "24.04.24-0"
        },
        {
            "introduced": "24.04.24-1"
        },
        {
            "last_affected": "24.04.24-1"
        },
        {
            "introduced": "24.04.24-2"
        },
        {
            "last_affected": "24.04.24-2"
        },
        {
            "introduced": "24.04.24-3"
        },
        {
            "last_affected": "24.04.24-3"
        }
    ],
    "cpe": [
        "cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24:1:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24:10:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24:2:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24:3:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24:4:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24:5:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24:6:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24:7:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24:8:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24:9:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:23.10.24.0:*:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:24.04.24:-:*:*:*:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:24.04.24:0:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:24.04.24:1:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:24.04.24:2:*:*:lts:*:*:*",
        "cpe:2.3:a:dotcms:dotcms:24.04.24:3:*:*:lts:*:*:*"
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ]
}

Affected versions

23.*
23.10.24-1
23.10.24-10
23.10.24-2
23.10.24-3
23.10.24-4
23.10.24-5
23.10.24-6
23.10.24-7
23.10.24-8
23.10.24-9
23.10.24.0
24.*
24.04.24-0
24.04.24-1
24.04.24-2
24.04.24-3
24.04.24-NA

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3938.json"