First published: Sun Aug 18 2024(Updated: )
A vulnerability classified as critical has been found in DedeBIZ 6.3.0. This affects the function AdminUpload of the file admin/archives_do.php. The manipulation of the argument litpic leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 | =6.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7905 is classified as a critical vulnerability.
To fix CVE-2024-7905, update DedeBIZ to the latest version that addresses this vulnerability.
CVE-2024-7905 allows for unrestricted file uploads, which can potentially lead to remote code execution.
CVE-2024-7905 affects DedeBIZ version 6.3.0.
Yes, CVE-2024-7905 can be exploited remotely.