CVE-2023-2424: DedeCMS config.php UpDateMemberModCache unrestricted upload
Published Apr 29, 2023
·Updated
A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uploads/dede/config.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227750 is the identifier assigned to this vulnerability.
Affected Software
1 affected component
DedeCMS Dedecms=5.7.106
Event History
Apr 29, 2023
CVE Published
07:31 AM
Data Sourced
07:31 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-2424?
The severity of CVE-2023-2424 is high, with a severity value of 8.8.
2
What is the affected software of CVE-2023-2424?
The affected software of CVE-2023-2424 is DedeCMS version 5.7.106.
3
What is the vulnerability in CVE-2023-2424?
The vulnerability in CVE-2023-2424 is an unrestricted upload issue in the DedeCMS function UpDateMemberModCache of the file uploads/dede/config.php.
4
How can the attack be launched for CVE-2023-2424?
The attack for CVE-2023-2424 can be launched remotely.
5
What is the CWE ID for CVE-2023-2424?
The CWE ID for CVE-2023-2424 is 434.