First published: Fri Apr 14 2023(Updated: )
A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issue is some unknown functionality of the file uploads/include/dialog/select_templets.php. The manipulation leads to path traversal: '..\filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225944.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | =5.7.87 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2059 is medium.
DedeCMS version 5.7.87 is affected by CVE-2023-2059.
The CWE ID for CVE-2023-2059 is CWE-22 and CWE-28.
The path traversal vulnerability in DedeCMS can be exploited by manipulating the file uploads/include/dialog/select_templets.php file and using '..\filedir' to perform the attack.
Yes, the references for CVE-2023-2059 are: [GitHub](https://github.com/ATZXC-RedTeam/cve/blob/main/dedecms.md), [VulDB](https://vuldb.com/?ctiid.225944), [VulDB](https://vuldb.com/?id.225944).