PatchSiren cyber security CVE debrief
CVE-2017-5877 Dotcms CVE debrief
CVE-2017-5877 describes a cross-site scripting (XSS) issue in dotCMS 3.7.0 that can be triggered without authentication through the /about-us/locations/index direction parameter. Because the flaw is reachable over the network and requires user interaction, it can be used to execute attacker-supplied script in a victim’s browser on affected deployments. NVD classifies the issue as CVSS v3.0 6.1 (MEDIUM) with scope changed and low confidentiality/integrity impact.
- Vendor
- Dotcms
- Product
- Unknown
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-06
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-06
- Advisory updated
- 2026-05-13
Who should care
Teams operating dotCMS 3.7.0 instances, especially public-facing sites that expose the affected /about-us/locations/index endpoint, should treat this as a web application input-validation and output-encoding issue. Security teams responsible for browser-side risk, session exposure, and content integrity should also review it.
Technical summary
The supplied NVD record maps CVE-2017-5877 to dotCMS 3.7.0 and CWE-79 (XSS). The vulnerability description indicates an unauthenticated attack against the /about-us/locations/index direction parameter. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) indicates remote exploitation with no privileges, required user interaction, and potential impact that crosses the browser trust boundary.
Defensive priority
Medium
Recommended defensive actions
- Confirm whether any dotCMS 3.7.0 deployments are still in service and inventory the exposed /about-us/locations/index path.
- Review server-side handling of the direction parameter and other user-controlled inputs for proper validation and output encoding.
- Use the linked vendor/security references to identify any patched release, workaround, or migration guidance.
- Add or verify browser-side mitigations such as a restrictive Content Security Policy where feasible.
- Monitor logs and application telemetry for suspicious query strings or repeated requests targeting the affected endpoint.
Evidence notes
This debrief is based on the supplied NVD CVE record and linked references. NVD lists dotCMS 3.7.0 as the vulnerable CPE and classifies the weakness as CWE-79. The CVSS v3.0 vector provided by NVD is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. The supplied corpus does not include a specific fixed version or patch identifier, so remediation guidance is limited to reviewing the official references.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5877 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5877
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5877 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5877
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/dotCMS/core/issues/10643
[email protected] - Exploit, Issue Tracking, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.