Description dotCMS是一个100%免费基于J2EE/portal的内容管理系统,它有着许多吸引人的特性是其它许多CMS所没有的。该系统存在任意文件上传漏洞,攻击者可以直接获取服务器权限。
Related VulnerabilitiesPoCCVE-2026-8054: dotCMS Core Publish Audit API - Unauthenticated SQL InjectiondotCMS /api/auditPublishing/getAll SQL 注入漏洞dotCMS Core /api/auditPublishing/getAll SQL 注入漏洞(CVE-2026-8054)PoCCVE-2018-17422: DotCMS < 5.0.2 - Open RedirectPoCCVE-2022-26352: DotCMS - Arbitrary File UploadPoCCVE-2022-26352: DotCMS Arbitrary File UploadDotCMS processFile CVE-2022-26352 目录遍历漏洞dotCMS _fixconflictsfromremote目录遍历漏洞dotCMS api/content 任意文件上传漏洞