CVE-2022-43192: Malicious File Upload
Published Nov 17, 2022
·Updated
An arbitrary file upload vulnerability in the component /dede/filemanagecontrol.php of Dedecms v5.7.101 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is related to an incomplete fix for CVE-2022-40886.
Affected Software
1 affected component
DedeCMS Dedecms=5.7.101
Event History
Nov 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID for this issue is CVE-2022-43192.
2
What is the affected software version?
The affected software version is Dedecms v5.7.101.
3
What is the severity level of this vulnerability?
The severity level of this vulnerability is medium.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by uploading a crafted PHP file through the /dede/file_manage_control.php component, which allows them to execute arbitrary code.
5
Is there a fix available for this vulnerability?
Yes, there is a fix available. It is recommended to update to a version that includes the fix for CVE-2022-40886.