CVE-2022-35516: Code Injection
Published Aug 17, 2022
·Updated
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
Affected Software
1 affected component
DedeCMS Dedecms>=5.7.93<=5.7.96
Remediation
Event History
Aug 17, 2022
CVE Published
via MITRE·07:09 PM
Data Sourced
via MITRE·07:09 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-35516?
The severity of CVE-2022-35516 is critical with a CVSS score of 9.8.
2
What is the affected software of CVE-2022-35516?
The affected software of CVE-2022-35516 is Dedecms v5.7.93 - v5.7.96.
3
What is the vulnerability description of CVE-2022-35516?
CVE-2022-35516 is a remote code execution vulnerability in login.php of Dedecms v5.7.93 - v5.7.96.
4
How can I fix CVE-2022-35516?
To fix CVE-2022-35516, update Dedecms to a version beyond v5.7.96 or apply any provided patches or fixes by the vendor.
5
Is there any reference for CVE-2022-35516?
Yes, you can find a reference for CVE-2022-35516 at the following link: [GitHub - Dedecms 5.7.93 Remote Code Execution](https://github.com/whitehatl/Vulnerability/blob/main/web/dedecms/5.7.93/Login.poc.md)