CVE-2024-46373: Malicious File Upload
Published Sep 18, 2024
·Updated
Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.
Affected Software
2 affected components
DedeCMS Dedecms
DedeCMS Dedecms=5.7.115
Event History
Sep 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-46373?
CVE-2024-46373 has been classified as a high severity vulnerability due to its potential for arbitrary code execution via file uploads.
2
How do I fix CVE-2024-46373?
To fix CVE-2024-46373, ensure that your Dedecms installation is updated to the latest version that patches this vulnerability.
3
What versions of Dedecms are affected by CVE-2024-46373?
CVE-2024-46373 affects Dedecms version V5.7.115 and potentially earlier versions.
4
What type of vulnerability is CVE-2024-46373?
CVE-2024-46373 is an arbitrary code execution vulnerability that allows attackers to upload malicious files.
5
Is there a workaround for CVE-2024-46373 before updating?
While the best approach is to update, temporarily restricting file uploads or implementing strict file validation may serve as a workaround for CVE-2024-46373.