CVE-2023-5022: DedeCMS select_templets_post.php absolute path traversal
Published Sep 17, 2023
·Updated
A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/selecttempletspost.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this vulnerability is VDB-239863.
Affected Software
1 affected component
DedeCMS Dedecms<=5.7.100
Event History
Sep 17, 2023
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-5022.
2
What is the severity of CVE-2023-5022?
The severity of CVE-2023-5022 is high, with a score of 8.8.
3
What is the affected software?
The affected software is DedeCMS up to version 5.7.100.
4
What is the vulnerability type?
The vulnerability type is path traversal.
5
How can I mitigate this vulnerability?
To mitigate this vulnerability, ensure that the software is updated to version 5.7.101 or later.