CVE-2023-2059: DedeCMS select_templets.php path traversal
A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issue is some unknown functionality of the file uploads/include/dialog/selecttemplets.php. The manipulation leads to path traversal: '..\filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225944.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2059?
The severity of CVE-2023-2059 is medium.
Which version of DedeCMS is affected by CVE-2023-2059?
DedeCMS version 5.7.87 is affected by CVE-2023-2059.
What is the CWE ID for CVE-2023-2059?
The CWE ID for CVE-2023-2059 is CWE-22 and CWE-28.
How can the path traversal vulnerability in DedeCMS be exploited?
The path traversal vulnerability in DedeCMS can be exploited by manipulating the file uploads/include/dialog/select_templets.php file and using '..\filedir' to perform the attack.
Are there any references for CVE-2023-2059?
Yes, the references for CVE-2023-2059 are: [GitHub](https://github.com/ATZXC-RedTeam/cve/blob/main/dedecms.md), [VulDB](https://vuldb.com/?ctiid.225944), [VulDB](https://vuldb.com/?id.225944).