Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-26352

Опубликовано: 17 июл. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 6.8
EPSS Критический

Описание

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*
Версия от 3.0 (включая) до 22.02 (включая)

EPSS

Процентиль: 100%
0.94337
Критический

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.

CVSS3: 9.8
fstec
почти 4 года назад

Уязвимость системы управления контентом dotCMS, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.94337
Критический

9.8 Critical

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other