PatchSiren cyber security CVE debrief
CVE-2017-5344 Dotcms CVE debrief
CVE-2017-5344 is a critical SQL injection flaw in dotCMS through 3.6.1. The vulnerable findChildrenByFilter() path is reachable through the web-accessible /categoriesServlet endpoint, and the documented SQL escaping and keyword blacklist can be bypassed for the q and inode parameters. Because the endpoint is reachable remotely without authentication in a default deployment, exposure can be high for internet-facing instances.
- Vendor
- Dotcms
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-17
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-17
- Advisory updated
- 2026-05-13
Who should care
dotCMS administrators, application owners, and security teams responsible for internet-facing or externally reachable dotCMS deployments through 3.6.1 should treat this as urgent. Database and incident response teams should also care because the flaw can be abused for blind boolean SQL injection and potential data exposure.
Technical summary
NVD classifies the issue as CWE-89 with CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The affected code path performs string interpolation and direct SQL query execution in findChildrenByFilter(), which is invoked by /categoriesServlet. Remediation logic added in SQLUtil for quote escaping and keyword blacklisting is described in the source record as bypassable for the q and inode parameters, leaving blind boolean SQL injection vectors available.
Defensive priority
Immediate. Prioritize patching or otherwise removing exposure of affected dotCMS instances, especially any deployment that exposes /categoriesServlet to untrusted networks.
Recommended defensive actions
- Apply the vendor remediation referenced by dotCMS security advisory SI-39 and move affected systems off versions through 3.6.1.
- Restrict external access to /categoriesServlet and the broader dotCMS admin/application surface until patched.
- Audit application and database logs for unusual /categoriesServlet requests, repeated parameter probing, or signs of blind SQL injection.
- Verify all dotCMS instances, including test and legacy systems, because default deployments may expose the vulnerable path remotely without authentication.
- Review any custom code, proxy rules, or WAF policies that might still allow direct access to the endpoint or help an attacker iterate on boolean-based SQL injection payloads.
Evidence notes
This debrief is grounded in the supplied NVD record and CVE metadata. The record states the issue affects dotCMS through 3.6.1, is reachable via /categoriesServlet, and can be exploited without authentication in a default deployment. NVD assigns CVSS 3.0 9.8/Critical and CWE-89. The source corpus also includes the vendor advisory reference SI-39 and third-party exploit references, but those are not used here beyond confirming public disclosure context.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5344 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5344
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5344 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5344
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/xdrr/webapp-exploits/blob/master/vendors/dotcms/2017.01.blind-sqli/dotcms-dump.sh
[email protected] - Exploit, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/41377/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.