First published: Sat Apr 29 2023(Updated: )
A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uploads/dede/config.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227750 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | =5.7.106 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2424 is high, with a severity value of 8.8.
The affected software of CVE-2023-2424 is DedeCMS version 5.7.106.
The vulnerability in CVE-2023-2424 is an unrestricted upload issue in the DedeCMS function UpDateMemberModCache of the file uploads/dede/config.php.
The attack for CVE-2023-2424 can be launched remotely.
The CWE ID for CVE-2023-2424 is 434.