Home / Companies / Sonar / Blog / Post Details
Content Deep Dive

dotCMS 5.1.5: Exploiting H2 SQL injection to RCE

Blog post from Sonar

Post Details
Company
Date Published
Author
Sonar
Word Count
908
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

The SQL injection vulnerability in dotCMS can be exploited by an unauthenticated attacker through CSRF or as a user with Publisher permissions, allowing arbitrary database entries and potentially Remote Code Execution if the H2 database is used. An attacker can exploit the Push Publishing feature to inject SQL syntax, and the lack of input sanitization and prepared statements makes it possible to execute stacked SQL queries. The vulnerability was reported in 2019 and addressed in release 5.1.6, which includes a URL filter that prevents exploitation by bypassing curly braces in URLs.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.