PT-2024-17473 · Dedecms · Dedecms

Jiashenghe

·

Published

2024-12-04

·

Updated

2024-12-10

·

CVE-2024-12181

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions DedeCMS version 5.7.116
Description A problematic vulnerability was found in DedeCMS, affecting an unknown functionality of the file /member/uploads add.php of the component SWF File Handler. The manipulation of the mediatype argument leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations For DedeCMS version 5.7.116, as a temporary workaround, consider restricting access to the /member/uploads add.php file until a patch is available. Avoid using the mediatype argument in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-12181

Affected Products

Dedecms