Skip to content
COOEY

EXPOSURES › CVE-2022-26352

CVE-2022-26352

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-08-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-26352 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

dotCMS allowed unrestricted file uploads leading to directory traversal and remote code execution.

An unrestricted file upload vulnerability in dotCMS enabled directory traversal and remote code execution, allowing attackers to save files outside intended locations and execute arbitrary code. DIB organizations must ensure content management systems strictly validate file types and paths to prevent similar exploits that could lead to system compromise and data breaches.

Shame score — A critical vulnerability allowing remote code execution was actively exploited in the wild and linked to ransomware, indicating severe negligence in patching and secure design.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.