Vulnerability Description
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dedecms | Dedecms | 5.7 |
Related Weaknesses (CWE)
References
- https://blog.csdn.net/qq_36093477/article/details/86681178ExploitThird Party Advisory
- https://blog.csdn.net/qq_36093477/article/details/86681178ExploitThird Party Advisory
FAQ
What is CVE-2020-18114?
CVE-2020-18114 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
How severe is CVE-2020-18114?
CVE-2020-18114 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-18114?
Check the references section above for vendor advisories and patch information. Affected products include: Dedecms Dedecms.