PT-2024-16783 · Dedecms · Dedecms
Falling-Snow
·
Published
2024-11-12
·
Updated
2024-12-10
·
CVE-2024-11138
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DedeCMS version 5.7.116
Description
A vulnerability has been found in DedeCMS, affecting the file /dede/uploads/dede/friendlink add.php. The manipulation of the
logoimg argument leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This issue poses a potential risk of remote code execution.Recommendations
For DedeCMS version 5.7.116, patch immediately to prevent potential exploitation and monitor for exploit attempts. As a temporary workaround, consider restricting access to the
friendlink add.php file or disabling the logoimg argument until a patch is available.Exploit
Fix
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dedecms