Description
dotCMS before 5.1.0 has a path traversal vulnerability exploitable by an administrator to create files. The vulnerability is caused by the insecure extraction of a ZIP archive.
Remediation
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2006-0552)
WebLogic CVE-2018-2987 Vulnerability (CVE-2018-2987)
MySQL CVE-2014-6551 Vulnerability (CVE-2014-6551)
Drupal Core 9.0.x Information Disclosure (9.0.0 - 9.0.5)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-5730)