First published: Mon Dec 18 2017(Updated: )
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | <=5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-17731 is considered critical due to its ability to facilitate SQL Injection attacks.
To fix CVE-2017-17731, upgrade DedeCMS to a version newer than 5.7 that has addressed this vulnerability.
The impact of CVE-2017-17731 includes potential unauthorized data access and the possibility of executing arbitrary SQL commands.
DedeCMS versions up to and including 5.7 are affected by CVE-2017-17731.
CVE-2017-17731 exploits the $_FILES superglobal by allowing attackers to inject malicious SQL queries through file upload requests.