S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-17422 Scanner

CVE-2018-17422 scanner - Open Redirect vulnerability in dotCMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-17422
6.1
CVSS

dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 18, 2026View on NVD →
Detail

In today's digital age, the importance of reliable and secure content management systems cannot be overstated. This is where dotCMS comes into play - a Java-based open-source CMS that enables organisations to create, manage and deliver content across various digital channels. dotCMS is widely used by organisations across a range of industries, including the healthcare, finance and retail sectors. The platform offers state-of-the-art tools for content creation, editing and publishing, as well as sophisticated workflows and multi-site management.

Unfortunately, like most software, dotCMS is not immune to vulnerabilities. One such vulnerability is CVE-2018-17422, which was detected in dotCMS before 5.0.2. This vulnerability is related to the software's open redirect feature, which meant that attackers could execute malicious code by manipulating the FORWARD_URL parameter or the hostname parameter in certain pages. Attackers could use this weakness to redirect users to malicious web pages or extract sensitive information from users who clicked on a seemingly harmless link.

The exploitation of CVE-2018-17422 can lead to many dangers for victims. For instance, attackers can use this vulnerability to launch phishing campaigns, where users are tricked into revealing confidential information such as passwords and credit card details. This vulnerability can also be used to initiate cyberattacks targeted at specific individuals, companies or organisations. Once the attacker has gained access to the victim's system, they can take full control and execute other malicious actions, such as installing malware or stealing proprietary information.

In conclusion, vulnerabilities like CVE-2018-17422 underline the importance of ensuring the security of your digital assets. s4e.io platform offers a wide range of pro features to help organisations monitor and protect their online presence in real-time, including vulnerability scans, threat intelligence, and incident response services. s4e.io is a trusted platform in helping stop cyber threats and keep the digital world secure. By leveraging these features, companies can ensure their systems are secure and users are protected from cyberattacks.

 

REFERENCES

Solution Advice

Fortunately, there are several ways to protect against this vulnerability. These precautions include:

  • Updating dotCMS to version 5.0.2 or later, where the vulnerability has been patched
  • Disabling open redirects in dotCMS altogether
  • Implementing web application firewalls (WAFs) to monitor and manage web traffic
  • Regularly scanning systems for vulnerabilities and patching them as soon as possible

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-17422 scanner - Open Redirect vulnerability in dotCMS | S4E