PT-2024-24091 · Dedecms · Dedecms

Urkc

·

Published

2024-04-02

·

Updated

2025-01-15

·

CVE-2024-3146

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions DedeCMS version 5.7
Description A problematic issue has been found in DedeCMS, affecting an unknown part of the file /src/dede/makehtml rss action.php. This issue leads to cross-site request forgery and can be initiated remotely. The exploit has been disclosed publicly. The vendor was contacted about this issue but did not respond.
Recommendations For DedeCMS version 5.7, consider restricting access to the /src/dede/makehtml rss action.php file as a temporary workaround until a patch is available.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-3146

Affected Products

Dedecms