CVE-2018-12045: Malicious File Upload
Published Jun 8, 2018
·Updated
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/filemanagecontrol.php via a dede/filemanageview.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.
Affected Software
4 affected components
DedeCMS Dedecms<5.7
DedeCMS Dedecms=5.7
DedeCMS Dedecms=5.7-sp1
DedeCMS Dedecms=5.7-sp2
Event History
Jun 8, 2018
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12045?
CVE-2018-12045 has a medium severity rating, primarily due to its potential for arbitrary file uploads.
2
How do I fix CVE-2018-12045?
To fix CVE-2018-12045, upgrade to Dedecms version 5.7 SP3 or later where the vulnerability is resolved.
3
What versions of DedeCMS are affected by CVE-2018-12045?
CVE-2018-12045 affects DedeCMS versions up to and including 5.7 SP2.
4
What type of vulnerability is CVE-2018-12045?
CVE-2018-12045 is classified as an arbitrary file upload vulnerability.
5
Can I exploit CVE-2018-12045 without authentication?
Yes, CVE-2018-12045 can be exploited without authentication, allowing attackers to upload malicious files.