PT-2023-31501 · Dedecms · Dedecms

·

CVE-2023-5022

·

Published

2023-09-16

·

Updated

2024-05-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DedeCMS versions up to 5.7.100
Description A critical issue has been found in DedeCMS, affecting an unknown functionality of the file /include/dialog/select templets post.php. The manipulation of the activepath argument leads to absolute path traversal.
Recommendations For DedeCMS versions up to 5.7.100, update to a version later than 5.7.100 to resolve the issue. As a temporary workaround, consider restricting access to the /include/dialog/select templets post.php file until a patch is available. Avoid manipulating the activepath argument in the affected file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-5022

Affected Products

Dedecms