Path Traversal Vulnerability in dotCMS by dotCMS
CVE-2019-12309
4.9MEDIUM
What is CVE-2019-12309?
dotCMS versions prior to 5.1.0 are susceptible to a path traversal vulnerability, allowing an administrator to manipulate file paths due to insecure handling of ZIP archives. This flaw could lead to unauthorized file creation, potentially compromising the integrity of the application. Mitigation involves upgrading to the latest version where this vulnerability has been resolved.
