References https://nosec.org/m/share/5007.html https://www.assetnote.io/resources/research/advisory-dotcms-remote-code-execution-cve-2022-26352 https://nvd.nist.gov/vuln/detail/CVE-2022-26352 https://medium.com/@urshilaravindran/cve-2022-26352-decoding-the-high-impact-rce-vulnerability-in-dotcms-d52535781e78 https://safe.security/resources/blog/dotcms-remote-code-execution/ https://www.cve.org/CVERecord?id=CVE-2022-26352 https://github.com/rapid7/metasploit-framework/issues/16522 https://www.acunetix.com/vulnerabilities/web/dotcms-unrestricted-file-upload-cve-2022-26352/ https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=33714 https://thehackernews.com/2022/05/critical-rce-bug-reported-in-dotcms.html https://pentest-tools.com/vulnerabilities-exploits/dotcms-remote-code-execution_87 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-26352.yaml https://www.sentinelone.com/vulnerability-database/cve-2022-26352/ https://github.com/advisories/GHSA-pr6q-gfg3-vcjf https://sara-open.sirp.io/kev/CVE-2022-26352
Related VulnerabilitiesPoCCVE-2026-8054: dotCMS Core Publish Audit API - Unauthenticated SQL InjectiondotCMS /api/auditPublishing/getAll SQL 注入漏洞dotCMS Core /api/auditPublishing/getAll SQL 注入漏洞(CVE-2026-8054)PoCCVE-2018-17422: DotCMS < 5.0.2 - Open RedirectPoCCVE-2022-26352: DotCMS - Arbitrary File UploadPoCCVE-2022-26352: DotCMS Arbitrary File UploaddotCMS任意文件上传(CVE-2022-26352)dotCMS _fixconflictsfromremote目录遍历漏洞dotCMS api/content 任意文件上传漏洞FOSS Gallery 'processFiles.php' 任意文件上传漏洞