← Vulnerability feed

Vulnerability record · CVE-2020-6754 · published 5 February 2020

CVE-2020-6754: dotCMS directory traversal and unrestricted file upload enable RCE

Dotcms · Dotcms

dotCMS before 5.2.4 is vulnerable to directory traversal that breaks access control on the $TOMCAT_HOME/webapps/ROOT/assets directory. Attackers can read or execute files there and upload temporary files such as .jsp into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution as the dotCMS application user.

9.8 CVSS 3.1 Critical EPSS 95% · top 0.1% CWE-22 · Path traversalCWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution (with the permissions of the user running the dotCMS application).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, and public exploit references makes this a critical pre-auth RCE risk.

What it is

dotCMS before 5.2.4 is vulnerable to directory traversal that breaks access control on the $TOMCAT_HOME/webapps/ROOT/assets directory. Attackers can read or execute files there and upload temporary files such as .jsp into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution as the dotCMS application user.

Impact

An unauthenticated attacker can read protected files and execute arbitrary code with the permissions of the dotCMS process, potentially taking full control of the host.

Attack surface

The flaw is reachable over the network via HTTP with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

No CISA KEV listing is present, but EPSS is 0.948 (99.855th percentile) and both references are tagged Exploit, indicating public exploit code exists and exploitation is likely.

What to do

  • Upgrade dotCMS to 5.2.4 or later immediately.
  • If patching is delayed, block or restrict access to /webapps/ROOT/assets and /webapps/ROOT/assets/tmp_upload at the web server or WAF.
  • Disable or remove any upload functionality that writes into the assets directory until the patch is applied.
  • Run dotCMS with a least-privilege OS account and restrict write permissions on the webapps directory.
  • Monitor the vendor advisory SI-54 for additional mitigations.

Detection

  • Inspect web and application logs for traversal sequences such as ../ or encoded variants targeting /assets paths.
  • Alert on file creation or modification events under webapps/ROOT/assets, especially .jsp files in tmp_upload.
  • Monitor for unexpected child processes spawned by the dotCMS Java process.
  • Review access logs for requests to /assets/tmp_upload or unusual file names in the assets directory.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://dotcms.com/security/SI-54 ExploitMitigationVendor Advisory
https://github.com/dotCMS/core/issues/17796 ExploitThird Party Advisory
https://dotcms.com/security/SI-54 ExploitMitigationVendor Advisory
https://github.com/dotCMS/core/issues/17796 ExploitThird Party Advisory

Track CVE-2020-6754 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26352dotCMS ContentResource API path traversal enables unauthenticated file upload RCEThe ContentResource API in dotCMS 3.0 through 22.02 fails to sanitize the filename in multipart form uploads, allowing directory traversal that write…KEVEPSS 92%analysed9.8CVE-2020-19138Dotcms unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src…EPSS 5.7%9.8CVE-2017-5344Dotcms sql injection vulnerabilityAn issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet pe…EPSS 6.3%9.8CVE-2016-2355Dotcms sql injection vulnerabilitySQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter…EPSS 2.1%9.8CVE-2016-8902Dotcms sql injection vulnerabilitySQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQ…EPSS 2.8%9.4CVE-2025-11165Dotcms sql injection vulnerabilityA sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to byp…EPSS 0.31%8.8CVE-2022-45782Dotcms vulnerabilityAn issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm f…EPSS 0.64%8.8CVE-2020-18875Dotcms injection vulnerabilityIncorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocit…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2020-6754), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.