Back to search
CVE-2016-4803
Published: Jun 30, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://dotcms.com/docs/latest/change-log#release-3.3.2
x_refsource_CONFIRM
91529
vdb-entry
x_refsource_BID
20160525 CVE-2016-4803 dotCMS - Email Header Injection
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now