dotCMS security briefs
1 published alerts for dotCMS products and services.
Actively exploited (KEV)Ransomware
dotCMS Unrestricted Upload of File Vulnerability
dotCMS dotCMS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-26352). dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution. CISA remediation due date: 2022-09-15. If you need help checking exposure, call (864) 335-9223.