CVE-2017-6003by Jeremyin Security Bulletinson Posted on March 28, 2017 dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.