SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-26352

dotCMS Unrestricted Upload of File Vulnerability

KEVCRITICAL 9.8EPSS 91.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
91.55% probability · 100th percentile
CISA KEV
Listed 25 August 2022 · due 15 September 2022 · used in ransomware campaigns
Affected
dotcms/dotcms
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://www.dotcms.com/security/SI-62; https://nvd.nist.gov/vuln/detail/CVE-2022-26352

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.