PT-2023-22229 · Dedecms · Dedecms

Wenqifeng

·

Publicado

2023-05-27

·

Atualizado

2024-05-17

·

CVE-2023-2928

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DedeCMS versions up to 5.7.106
Description A critical issue affects an unknown functionality of the file uploads/dede/article allowurl edit.php. The manipulation of the allurls argument leads to code injection. The attack can be launched remotely.
Recommendations For versions up to 5.7.106, consider disabling the functionality related to the allurls argument in the uploads/dede/article allowurl edit.php file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-2928

Produtos afetados

Dedecms