PT-2022-27114 · Dedecmdv6 · Dedecmdv6

Yinfei6

·

Published

2022-11-23

·

Updated

2025-04-28

·

CVE-2022-44118

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dedecmdv6 version 6.1.9
Description The issue allows for Remote Code Execution (RCE) via the file manage control.php endpoint.
Recommendations For dedecmdv6 version 6.1.9, consider restricting access to the file manage control.php endpoint until a patch is available.

Fix

Related Identifiers

CVE-2022-44118

Affected Products

Dedecmdv6