Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.
No PoCs from references.
- https://github.com/Live-Hack-CVE/CVE-2020-18875