CVE-2023-37839: Malicious File Upload
Published Jul 13, 2023
·Updated
An arbitrary file upload vulnerability in /dede/filemanagecontrol.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Affected Software
1 affected component
DedeCMS Dedecms=5.7.109
Event History
Jul 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
10:15 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-37839.
2
What is the severity of CVE-2023-37839?
The severity of CVE-2023-37839 is critical with a score of 9.8.
3
What is the affected software of CVE-2023-37839?
The affected software of CVE-2023-37839 is DedeCMS version 5.7.109.
4
How does the vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allow attackers to execute arbitrary code?
The vulnerability allows attackers to execute arbitrary code by uploading a crafted PHP file.
5
Is there a fix available for this vulnerability?
Yes, updating DedeCMS to a version that has fixed this vulnerability is the recommended solution.