PT-2023-22229 · Dedecms · Dedecms

Wenqifeng

·

Published

2023-05-27

·

Updated

2024-05-17

·

CVE-2023-2928

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DedeCMS versions up to 5.7.106
Description A critical issue affects an unknown functionality of the file uploads/dede/article allowurl edit.php. The manipulation of the allurls argument leads to code injection. The attack can be launched remotely.
Recommendations For versions up to 5.7.106, consider disabling the functionality related to the allurls argument in the uploads/dede/article allowurl edit.php file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-2928

Affected Products

Dedecms