First published: Thu May 23 2024(Updated: )
There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-35375 is considered a critical vulnerability due to its potential for arbitrary file upload, which can lead to remote code execution.
To fix CVE-2024-35375, upgrade your DedeCMS installation to a patched version or restrict file upload capabilities on the media add .php page.
CVE-2024-35375 affects version 5.7.114 of DedeCMS.
Exploitation of CVE-2024-35375 can allow attackers to upload malicious files and potentially execute arbitrary code on the server.
You can determine if your DedeCMS installation is vulnerable to CVE-2024-35375 by checking if you are running version 5.7.114 and testing the media add .php page for file upload weaknesses.