CVE-2023-34842: Code Injection
Published Jul 31, 2023
·Updated
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
Affected Software
1 affected component
DedeCMS Dedecms<=5.7.109
Event History
Jul 31, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-34842?
CVE-2023-34842 is a Remote Code Execution vulnerability in DedeCMS through 5.7.109.
2
How does CVE-2023-34842 affect DedeCMS?
CVE-2023-34842 allows remote attackers to run arbitrary code via a crafted POST request to /dede/tpl.php.
3
What is the severity of CVE-2023-34842?
CVE-2023-34842 has a severity rating of 9.8 (Critical).
4
How can I fix CVE-2023-34842?
To fix CVE-2023-34842, upgrade DedeCMS to version 5.7.110 or higher.
5
Where can I find more information about DedeCMS?
You can find more information about DedeCMS at https://www.dedecms.com/.