EXPOSURES › CVE-2022-26352
CVE-2022-26352
CRITICAL ⌖ ON CISA KEV · EXPLOITEDdotCMS allowed unrestricted file uploads leading to directory traversal and remote code execution.
An unrestricted file upload vulnerability in dotCMS enabled directory traversal and remote code execution, allowing attackers to save files outside intended locations and execute arbitrary code. DIB organizations must ensure content management systems strictly validate file types and paths to prevent similar exploits that could lead to system compromise and data breaches.
Shame score — A critical vulnerability allowing remote code execution was actively exploited in the wild and linked to ransomware, indicating severe negligence in patching and secure design.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.