First published: Thu Nov 17 2022(Updated: )
An arbitrary file upload vulnerability in the component /dede/file_manage_control.php of Dedecms v5.7.101 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is related to an incomplete fix for CVE-2022-40886.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | =5.7.101 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-43192.
The affected software version is Dedecms v5.7.101.
The severity level of this vulnerability is medium.
An attacker can exploit this vulnerability by uploading a crafted PHP file through the /dede/file_manage_control.php component, which allows them to execute arbitrary code.
Yes, there is a fix available. It is recommended to update to a version that includes the fix for CVE-2022-40886.