First published: Tue May 14 2024(Updated: )
An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34245 is considered a high severity vulnerability due to the potential for arbitrary file reading by authenticated attackers.
To fix CVE-2024-34245, update your DedeCMS to the latest version that addresses this vulnerability.
CVE-2024-34245 affects all authenticated users of DedeCMS v5.7.114.
CVE-2024-34245 is classified as an arbitrary file read vulnerability.
CVE-2024-34245 requires authentication, but once authenticated, attackers can exploit it remotely to read arbitrary files.