CVE-2025-8311 is a critical Boolean-based blind SQL injection vulnerability affecting dotCMS versions 24.03.22 and later, specifically within the /api/v1/contenttype endpoint. An authenticated, low-privileged attacker can exploit this by manipulating the 'sites' query parameter, which is directly concatenated into SQL queries without proper sanitization. This allows for full database exfiltration, privilege escalation, and denial-of-service conditions, as confirmed by tools like SQLMap. The vulnerability has a CVSS score of 9.4 (CRITICAL) due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not actively exploited in the wild or listed in CISA KEV, an ExploitDB entry (EDB-52431) exists, and the vulnerability has minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| DotCMS | DotCMS Cloud Services (DCS) | 24.03.22+CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.