CVE-2022-26352β€”dotCMS Unrestricted Upload of File Vulnerability

PUBLISHEDvulnerability record
2022-08-25 Β· last modified June 21, 2025

Metadata

CVE ID:
CVE-2022-26352
Project:
dotCMS
Product:
dotCMS
Date Added:
2022-08-25
Due Date:
2022-09-15
Last Updated:
June 21, 2025

Vulnerability Name

dotCMS Unrestricted Upload of File Vulnerability

Description

dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply updates per vendor instructions.

Additional Notes

Related Weaknesses