CVE-2023-43234: Code Injection
Published Sep 26, 2023
·Updated
DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/filemanagecontrol.php via the $activepath and $filename parameters.
Affected Software
1 affected component
DedeBIZ DedeBIZ=6.2.11
Event History
Sep 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 27, 2023
Data Sourced
via NVD·03:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-43234?
CVE-2023-43234 refers to multiple remote code execution vulnerabilities found in DedeBIZ v6.2.11 at /admin/file_manage_control.php via the $activepath and $filename parameters.
2
What is the severity of CVE-2023-43234?
The severity of CVE-2023-43234 is critical with a CVSS score of 9.8.
3
How can I fix CVE-2023-43234?
To fix CVE-2023-43234, it is recommended to update DedeBIZ to a version that addresses the remote code execution vulnerabilities.
4
Where can I find more information about CVE-2023-43234?
You can find more information about CVE-2023-43234 on the official DedeBIZ website (http://dedebiz.com) and the GitHub repository of the discoverer (https://github.com/yux1azhengye).