Arbitrary File Upload Vulnerability in DedeCMS v5.7.114 Allows Execution of Arbitrary Code via Upload
CVE-2024-35510

9.8CRITICAL

Key Information:

Vendor
DedeCMS
Status
Vendor
CVE Published:
28 May 2024

Summary

An arbitrary file upload vulnerability exists in the file management functionality of DedeCMS v5.7.114. This flaw allows attackers to upload specially crafted files that may lead to the execution of arbitrary code on the server. The vulnerability resides in the /dede/file_manage_control.php script, which fails to properly validate user inputs during file uploads. Attackers can exploit this weakness to compromise the integrity of the system, potentially leading to unauthorized access and control over affected systems.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.