Arbitrary File Upload Vulnerability in DedeCMS v5.7.114 Allows Execution of Arbitrary Code via Upload
CVE-2024-35510
9.8CRITICAL
Summary
An arbitrary file upload vulnerability exists in the file management functionality of DedeCMS v5.7.114. This flaw allows attackers to upload specially crafted files that may lead to the execution of arbitrary code on the server. The vulnerability resides in the /dede/file_manage_control.php script, which fails to properly validate user inputs during file uploads. Attackers can exploit this weakness to compromise the integrity of the system, potentially leading to unauthorized access and control over affected systems.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published