Vulnerability Intelligence Report
dotCMS Unrestricted Upload of File Vulnerability
CVE-2022-26352
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:91.50%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22 (via CISA KEV)
CWE-138 ↗CWE-138 (via CISA KEV)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| dotcms | dotcms | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
91.501%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2022-03-02T00:00:00 |
| Published | 2022-07-17T21:54:53 |
| Last Updated | 2025-10-21T23:15:38 |
Community Chatter & Buzz