CRITICAL

CVE-2020-6754

CVSS v3

9.8

CRITICAL

EPSS Score

75.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution (with the permissions of the user running the dotCMS application).

Technical details

Published
2/5/2020

Frequently asked questions

What is CVE-2020-6754?

dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution (with the permissions of the user running the dotCMS application).

Is CVE-2020-6754 actively exploited?

Active exploitation of CVE-2020-6754 has not been confirmed. The EPSS score is 75.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-6754?

CVE-2020-6754 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-6754 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.