PT-2022-26791 · Dedecms · Dedecms
Published
2022-11-17
·
Updated
2025-04-29
·
CVE-2022-43192
CVSS v3.1
6.7
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dedecms version 5.7.101
Description
The issue is related to an arbitrary file upload vulnerability in the /dede/file manage control.php component, allowing attackers to execute arbitrary code by uploading a crafted PHP file. This vulnerability is connected to an incomplete fix for a previous issue.
Recommendations
For Dedecms version 5.7.101, consider restricting access to the /dede/file manage control.php component until a proper fix is applied to prevent arbitrary file uploads. As a temporary workaround, disabling the execution of uploaded files or implementing strict upload validation can help mitigate the risk of code execution.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dedecms