PT-2024-30086 · Dedecms · Dedecms

Published

2024-08-23

·

Updated

2025-03-31

·

CVE-2024-42636

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DedeCMS version 5.7.115
Description DedeCMS has a command execution vulnerability via the "file manage view.php" endpoint with parameters fmdo=newfile and activepath. This issue allows for command execution. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For DedeCMS version 5.7.115, as a temporary workaround, consider restricting access to the "file manage view.php" endpoint with parameters fmdo=newfile and activepath until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-42636

Affected Products

Dedecms