DotCMS management system contains an arbitrary file upload vulnerability via the /api/content/ path which can allow attackers to upload malicious Trojans to obtain server permissions.
id: CVE-2022-26352
info:
name: DotCMS - Arbitrary File Upload
author: h1ei1
severity: critica
...