First published: Wed Dec 04 2024(Updated: )
A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown functionality of the file /member/uploads_add.php of the component SWF File Handler. The manipulation of the argument mediatype leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 | <5.7.116 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12181 is classified as problematic, indicating a significant risk to affected systems.
To fix CVE-2024-12181, update DedeCMS to a version newer than 5.7.116 that addresses this vulnerability.
CVE-2024-12181 is identified as a cross site scripting (XSS) vulnerability.
CVE-2024-12181 affects the SWF File Handler functionality in the file /member/uploads_add.php.
Exploiting CVE-2024-12181 can allow attackers to execute arbitrary JavaScript code in the context of an affected user's browser.