CVE-2022-26352
dotCMS Unrestricted Upload of File Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 91.55% probability · 100th percentile
- CISA KEV
- Listed 25 August 2022 · due 15 September 2022 · used in ransomware campaigns
- Affected
- dotcms/dotcms
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://www.dotcms.com/security/SI-62; https://nvd.nist.gov/vuln/detail/CVE-2022-26352
References
- http://packetstormsecurity.com/files/167365/dotCMS-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://groups.google.com/g/dotcmsPermissions Required, Third Party Advisory
- http://packetstormsecurity.com/files/167365/dotCMS-Shell-Upload.htmlExploit, Third Party Advisory, VDB Entry
- https://groups.google.com/g/dotcmsPermissions Required, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26352US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.