CVE-2025-11165 | dotCMS 24.12/25.07 Velocity Scripting Engine sql injection (EUVD-2025-207542)
A vulnerability has been found in dotCMS 24.12/25.07 and classified as critical. This affects an unknown part of the component Velocity Scripting Engine. The manipulation leads to sql injection.
This vulnerability is referenced as CVE-2025-11165. Remote exploitation of the attack is possible. No exploit is available.