CVE-2023-43226: Malicious File Upload
Published Sep 28, 2023
·Updated
An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
Affected Software
1 affected component
DedeCMS Dedecms<=5.7.111
Event History
Sep 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-43226?
CVE-2023-43226 is an arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier.
2
How does CVE-2023-43226 impact DedeCMS?
CVE-2023-43226 allows attackers to execute arbitrary code by uploading a crafted PHP file.
3
What is the severity of CVE-2023-43226?
CVE-2023-43226 has a severity rating of high with a CVSS score of 8.8.
4
How can I fix CVE-2023-43226?
To fix CVE-2023-43226, update DedeCMS to version 5.7.112 or above, which contains a patch for the vulnerability.
5
What is the Common Weakness Enumeration (CWE) number for CVE-2023-43226?
The CWE number for CVE-2023-43226 is CWE-434.