CVE-2020-6754
Last modified
CVE-2020-6754 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). EPSS estimates a 94.80% chance of exploitation in the next 30 days.
Description
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution (with the permissions of the user running the dotCMS application).
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dotcms | Dotcms | < 5.2.4 |
References
- https://dotcms.com/security/SI-54Exploit, Mitigation, Vendor Advisory
- https://github.com/dotCMS/core/issues/17796Exploit, Third Party Advisory
- https://dotcms.com/security/SI-54Exploit, Mitigation, Vendor Advisory
- https://github.com/dotCMS/core/issues/17796Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-6754?
How severe is CVE-2020-6754?
How do I fix CVE-2020-6754?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-6747Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-6748Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-6749Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-6750GSocketClient in GNOME GLib through 2.62.4 may occasionally …5.9
- CVE-2020-6752In OMERO before 5.6.1, group owners can access members' data…3.8
- CVE-2020-6753The Login by Auth0 plugin before 4.0.0 for WordPress allows …6.1
- CVE-2020-6756languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-2…9.8
- CVE-2020-6757contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.…8.8
- CVE-2020-6758A cross-site scripting (XSS) vulnerability in Option/options…6.1
- CVE-2020-6760Schmid ZI 620 V400 VPN 090 routers allow an attacker to exec…9.8
- CVE-2020-6764Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-6765D-Link DSL-GS225 J1 AU_1.0.4 devices allow an admin to execu…7.2
Are you affected by CVE-2020-6754?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
