Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2022-26352

dotCMS | dotCMSAdded 2022-08-25Remediation Deadline 2022-09-15Active Ransomware Campaign

dotCMS Unrestricted Upload of File Vulnerability

dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-22

CWE-138

References