PT-2024-16783 · Dedecms · Dedecms

Falling-Snow

·

Published

2024-11-12

·

Updated

2024-12-10

·

CVE-2024-11138

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DedeCMS version 5.7.116
Description A vulnerability has been found in DedeCMS, affecting the file /dede/uploads/dede/friendlink add.php. The manipulation of the logoimg argument leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This issue poses a potential risk of remote code execution.
Recommendations For DedeCMS version 5.7.116, patch immediately to prevent potential exploitation and monitor for exploit attempts. As a temporary workaround, consider restricting access to the friendlink add.php file or disabling the logoimg argument until a patch is available.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-11138

Affected Products

Dedecms