Vulnerability record · CVE-2020-6754 · published 5 February 2020
CVE-2020-6754: dotCMS directory traversal and unrestricted file upload enable RCE
Dotcms · Dotcms
dotCMS before 5.2.4 is vulnerable to directory traversal that breaks access control on the $TOMCAT_HOME/webapps/ROOT/assets directory. Attackers can read or execute files there and upload temporary files such as .jsp into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution as the dotCMS application user.
Description
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution (with the permissions of the user running the dotCMS application).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and public exploit references makes this a critical pre-auth RCE risk.
What it is
dotCMS before 5.2.4 is vulnerable to directory traversal that breaks access control on the $TOMCAT_HOME/webapps/ROOT/assets directory. Attackers can read or execute files there and upload temporary files such as .jsp into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution as the dotCMS application user.
Impact
An unauthenticated attacker can read protected files and execute arbitrary code with the permissions of the dotCMS process, potentially taking full control of the host.
Attack surface
The flaw is reachable over the network via HTTP with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
No CISA KEV listing is present, but EPSS is 0.948 (99.855th percentile) and both references are tagged Exploit, indicating public exploit code exists and exploitation is likely.
What to do
- Upgrade dotCMS to 5.2.4 or later immediately.
- If patching is delayed, block or restrict access to /webapps/ROOT/assets and /webapps/ROOT/assets/tmp_upload at the web server or WAF.
- Disable or remove any upload functionality that writes into the assets directory until the patch is applied.
- Run dotCMS with a least-privilege OS account and restrict write permissions on the webapps directory.
- Monitor the vendor advisory SI-54 for additional mitigations.
Detection
- Inspect web and application logs for traversal sequences such as ../ or encoded variants targeting /assets paths.
- Alert on file creation or modification events under webapps/ROOT/assets, especially .jsp files in tmp_upload.
- Monitor for unexpected child processes spawned by the dotCMS Java process.
- Review access logs for requests to /assets/tmp_upload or unusual file names in the assets directory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://dotcms.com/security/SI-54 | ExploitMitigationVendor Advisory |
| https://github.com/dotCMS/core/issues/17796 | ExploitThird Party Advisory |
| https://dotcms.com/security/SI-54 | ExploitMitigationVendor Advisory |
| https://github.com/dotCMS/core/issues/17796 | ExploitThird Party Advisory |
Track CVE-2020-6754 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-6754), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.