First published: Fri Aug 27 2021(Updated: )
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | =5.7-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-18114 is critical with a score of 9.8.
The affected software for CVE-2020-18114 is DedeCMS version 5.7SP2.
CVE-2020-18114 is an arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2, which allows attackers to upload a webshell in HTM format.
Attackers can exploit CVE-2020-18114 by uploading a malicious webshell in HTM format through the /uploads/dede component of DedeCMS V5.7SP2.
At the moment, there may not be an official fix available for CVE-2020-18114. It is recommended to mitigate the risk by implementing security best practices and restricting file uploads.