Critical severity9.8NVD Advisory· Published Sep 8, 2021· Updated Jun 17, 2026
CVE-2020-19138
CVE-2020-19138
Description
Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src/main/java/com/dotmarketing/filters/CMSFilter.java".
Affected products
3- DotCMS/DotCMSdescription
Patches
Vulnerability mechanics
References
1- github.com/dotCMS/core/issues/17796nvdExploitIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.