← Back to browse · API

CVE-2022-26352

Severity
CRITICAL
CVSS
9.8
EPSS
0.91079
Risk score
56.88
CISA KEV
Yes
PoC
No
Published
2022-07-17
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-30911, GHSA-PR6Q-GFG3-VCJF
Products
dotCMS:dotCMS, n/a:n/a n/a
Sources
cisa.gov CVE-2022-26352
euvd EUVD-2022-30911

Description

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.

References