{"id":"CVE-2024-3938","details":"The \"reset password\" login page accepted an HTML injection via URL parameters.\n\nThis has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a  http://localhost:8082/dotAdmin/#/public/login?resetEmailSent=true&resetEmail=%3Ch1%3E%3Ca%20href%3D%22https:%2F%2Fgoogle.com%22%3ECLICK%20ME%3C%2Fa%3E%3C%2Fh1%3E \n\nThis will result in a view along these lines:\n\n\n\n\n\n  *  OWASP Top 10 - A03: Injection\n  *  CVSS Score: 5.4\n  *   AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator \n  *   https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N&... https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator","modified":"2026-08-12T03:51:19.274860761Z","published":"2024-07-25T21:17:49.359Z","database_specific":{"cwe_ids":["CWE-20"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/3xxx/CVE-2024-3938.json","unresolved_ranges":[{"extracted_events":[{"introduced":"5.1.5 and after"},{"last_affected":"5.1.5 and after"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"dotCMS"},"references":[{"type":"WEB","url":"https://www.dotcms.com/security/SI-71"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/3xxx/CVE-2024-3938.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3938"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dotcms/core","events":[{"introduced":"ecc5abc7d7615e24c083c41483319e34243211a0"},{"fixed":"976f31730557c1e3f120ee85710e621cfa6c06a9"},{"introduced":"3feb6fa6ebdcf1509252fbf9ee7e53017c8bf96f"},{"last_affected":"20de9e9f791d40b6655c3cd506d74fce8fcb4f2d"},{"introduced":"1122a5760e412966e13d35f75436cb6fcd6f5d60"},{"last_affected":"703fb5c3d30f99779a10e0f7a1543c17033becd1"},{"introduced":"cc91f975b70b3f77a1b28c51ef504b965baf2896"},{"fixed":"8fac77cf07a65bbd0780f4f029b70d23eee02f5c"},{"introduced":"e32f4c872fbd0576ce4587aacaa26cc2995b9ce5"},{"last_affected":"de4c9e76227dcd1f6f885d52077f741de4d4de0c"}],"database_specific":{"extracted_events":[{"introduced":"5.1.5"},{"fixed":"23.01.18"},{"introduced":"23.02"},{"last_affected":"23.09.7"},{"introduced":"23.12.21"},{"last_affected":"24.04.23"},{"introduced":"24.05.13"},{"fixed":"24.05.31"},{"introduced":"23.10.24-1"},{"last_affected":"23.10.24-1"},{"introduced":"23.10.24-10"},{"last_affected":"23.10.24-10"},{"introduced":"23.10.24-2"},{"last_affected":"23.10.24-2"},{"introduced":"23.10.24-3"},{"last_affected":"23.10.24-3"},{"introduced":"23.10.24-4"},{"last_affected":"23.10.24-4"},{"introduced":"23.10.24-5"},{"last_affected":"23.10.24-5"},{"introduced":"23.10.24-6"},{"last_affected":"23.10.24-6"},{"introduced":"23.10.24-7"},{"last_affected":"23.10.24-7"},{"introduced":"23.10.24-8"},{"last_affected":"23.10.24-8"},{"introduced":"23.10.24-9"},{"last_affected":"23.10.24-9"},{"introduced":"23.10.24.0"},{"last_affected":"23.10.24.0"},{"introduced":"24.04.24-NA"},{"last_affected":"24.04.24-NA"},{"introduced":"24.04.24-0"},{"last_affected":"24.04.24-0"},{"introduced":"24.04.24-1"},{"last_affected":"24.04.24-1"},{"introduced":"24.04.24-2"},{"last_affected":"24.04.24-2"},{"introduced":"24.04.24-3"},{"last_affected":"24.04.24-3"}],"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:1:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:10:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:2:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:3:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:4:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:5:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:6:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:7:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:8:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:9:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24.0:*:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:24.04.24:-:*:*:*:*:*:*","cpe:2.3:a:dotcms:dotcms:24.04.24:0:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:24.04.24:1:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:24.04.24:2:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:24.04.24:3:*:*:lts:*:*:*"]}}],"versions":["23.10.24-1","23.10.24-10","23.10.24-2","23.10.24-3","23.10.24-4","23.10.24-5","23.10.24-6","23.10.24-7","23.10.24-8","23.10.24-9","23.10.24.0","24.04.24-0","24.04.24-1","24.04.24-2","24.04.24-3","24.04.24-NA"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3938.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}