Junglewise Threat Intelligence

CVE-2022-26352: dotCMS Unrestricted Upload of File Vulnerability

CVE-2022-26352 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-08-25

Technologies: dotCMS. Vendors: dotCMS.

Executive brief

The dotCMS ContentResource API fails to sanitize filenames in multipart form requests, allowing for directory traversal during file uploads. An unauthenticated attacker can exploit this to upload executable files (e.g., .jsp) outside the intended storage directory, leading to remote code execution.

Affected products

  • dotCMS dotCMS 3.0 through 22.02

Timeline

  • 2022-07-17: disclosed: NVD Published Date
  • 2022-08-25: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-08-25: advisory: Published date provided in advisory title
  • 2022-08-25: exploited: Reported as exploited in the wild and added to CISA KEV

Related threats