Skip to main content

dotCMS security briefs

1 published alerts for dotCMS products and services.

Actively exploited (KEV)Ransomware

CVE-2022-26352

dotCMS Unrestricted Upload of File Vulnerability

dotCMS dotCMS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-26352). dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution. CISA remediation due date: 2022-09-15. If you need help checking exposure, call (864) 335-9223.