2024-05-26 14:27:05 +02:00
### [CVE-2016-4803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4803)



### Description
CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject.
### POC
#### Reference
- http://seclists.org/fulldisclosure/2016/May/69
2024-06-09 00:33:16 +00:00
- http://seclists.org/fulldisclosure/2016/May/69
2024-05-26 14:27:05 +02:00
- https://dotcms.com/docs/latest/change-log#release -3.3.2
2024-06-09 00:33:16 +00:00
- https://dotcms.com/docs/latest/change-log#release -3.3.2
2024-05-26 14:27:05 +02:00
- https://security.elarlang.eu/cve-2016-4803-dotcms-email-header-injection-vulnerability-full-disclosure.html
2024-06-09 00:33:16 +00:00
- https://security.elarlang.eu/cve-2016-4803-dotcms-email-header-injection-vulnerability-full-disclosure.html
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.