← KEV catalog
CISA known exploited vulnerability

CVE-2022-26352

dotCMS Unrestricted Upload of File Vulnerability

SOURCE FACT

dotCMS · dotCMS

dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.

Required action

Apply updates per vendor instructions.

CISA notes

https://www.dotcms.com/security/SI-62; https://nvd.nist.gov/vuln/detail/CVE-2022-26352

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?