S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-26352 Scanner

CVE-2022-26352 scanner - Unrestricted File Upload vulnerability in dotCMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-26352
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

DotCMS is a popular content management system used for creating and managing websites, intranets, and other digital assets. It allows organizations to efficiently publish and update content across various platforms, including web, mobile, and social media. DotCMS provides a wide range of functionalities, including content authoring, workflow management, personalization, and integration with third-party systems.

One of the recent vulnerabilities detected in dotCMS is CVE-2022-26352. This vulnerability allows attackers to exploit a flaw in the ContentResource API, which processes multipart form requests to upload files. The issue arises when the API fails to sanitize the file names, allowing attackers to use directory traversal techniques to save files outside the intended storage location. If anonymous content creation is enabled, unauthenticated attackers can upload malicious files, such as .jsp files, that can result in remote code execution.

The exploitation of CVE-2022-26352 can lead to severe consequences for organizations using dotCMS. Attackers can gain unauthorized access to systems, steal sensitive information, or launch DDoS attacks. They can also take advantage of the compromised systems to distribute malware or launch attacks on other systems. Organizations may face reputational damage, legal liabilities, or financial loss due to the impact of such cyberattacks.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. With threat intelligence, vulnerability scanning, and risk monitoring capabilities, s4e.io can help organizations stay ahead of cyber threats and protect their systems, data, and customers.

 

REFERENCES

Solution Advice

To protect against CVE-2022-26352 and other vulnerabilities in dotCMS, organizations can take the following precautions:

  • Update to the latest version of dotCMS that includes a fix for this vulnerability.
  • Disable anonymous content creation if not needed.
  • Implement access controls and permissions to restrict file uploads and executions.
  • Enable content validation and sanitization to screen out malicious files.
  • Conduct regular security assessments and penetration testing to identify and mitigate vulnerabilities in dotCMS and other digital assets.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.