CyberRota Analysis
AI-GeneratedImproper authorization vulnerabilities in the ToolGroupResource and RoleAjax REST/DWR endpoints of dotCMS versions 21.02 through 26.06.22-03 allow low-privileged authenticated backend users to self-assign administrative roles and execute arbitrary shell commands through crafted OSGi bundle uploads. This could lead to remote code execution, posing significant risks to the integrity and security of the affected systems. Organizations using these versions of dotCMS should prioritize remediation to prevent potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a crafted OSGi bundle upload whose BundleActivator executes arbitrary shell commands.