CVE-2020-18114: Malicious File Upload
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-18114?
The severity of CVE-2020-18114 is critical with a score of 9.8.
What is the affected software for CVE-2020-18114?
The affected software for CVE-2020-18114 is DedeCMS version 5.7SP2.
What is the vulnerability description for CVE-2020-18114?
CVE-2020-18114 is an arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2, which allows attackers to upload a webshell in HTM format.
How can this vulnerability be exploited?
Attackers can exploit CVE-2020-18114 by uploading a malicious webshell in HTM format through the /uploads/dede component of DedeCMS V5.7SP2.
Is there a fix available for CVE-2020-18114?
At the moment, there may not be an official fix available for CVE-2020-18114. It is recommended to mitigate the risk by implementing security best practices and restricting file uploads.