Description
DotCMS allows an unauthenticated user to upload arbitrary files. An attacker can exploit it to achieve remote code execution.
Remediation
Upgrade to the latest version of DotCMS
References
Related Vulnerabilities
LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2018-16397)
Plone CMS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-5500)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-5625)
MySQL Other Vulnerability (CVE-2001-1255)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-34467)