PT-2023-22229 · Dedecms · Dedecms

·

CVE-2023-2928

·

Published

2023-05-27

·

Updated

2024-05-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DedeCMS versions up to 5.7.106
Description A critical issue affects an unknown functionality of the file uploads/dede/article allowurl edit.php. The manipulation of the allurls argument leads to code injection. The attack can be launched remotely.
Recommendations For versions up to 5.7.106, consider disabling the functionality related to the allurls argument in the uploads/dede/article allowurl edit.php file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-2928

Affected Products

Dedecms