CVE-2017-11466
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName parameter to servlets/ajax_file_upload. This results in arbitrary code execution by requesting the .jsp file at a /assets URI.
- CVSS 3.0
- 7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 7.70% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- dotcms/dotcms
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2017/Jul/33Exploit, Mailing List, Third Party Advisory
- https://github.com/dotCMS/core/issues/12131Issue Tracking, Patch, Third Party Advisory
- https://packetstormsecurity.com/files/143383/dotcms411-shell.txtExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2017/Jul/33Exploit, Mailing List, Third Party Advisory
- https://github.com/dotCMS/core/issues/12131Issue Tracking, Patch, Third Party Advisory
- https://packetstormsecurity.com/files/143383/dotcms411-shell.txtExploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.