CVE-2022-26352
dotCMS Unrestricted Upload of File Vulnerability
Description
dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.
Severity: CRITICAL
CVSS Score: 9.8
Vendor: dotCMS
Product: dotCMS
Loading CVE details...