CVE-2025-14648: DedeBIZ catalog_add.php command injection
A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown functionality of the file /src/admin/catalogadd.php. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14648?
CVE-2025-14648 is considered a critical security vulnerability due to its potential for remote command injection.
How do I fix CVE-2025-14648?
To fix CVE-2025-14648, you should update DedeBIZ to version 6.5.10 or later, which addresses this vulnerability.
What does CVE-2025-14648 affect?
CVE-2025-14648 affects DedeBIZ versions up to 6.5.9, specifically the functionality in the file /src/admin/catalog_add.php.
Can CVE-2025-14648 be exploited remotely?
Yes, CVE-2025-14648 can be exploited remotely due to the nature of the command injection vulnerability.
Who is the vendor for CVE-2025-14648?
The vendor for CVE-2025-14648 is DedeBIZ, the company behind the affected software.