Vulnerability Description
There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS
CVSS Score
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dedecms | Dedecms | 5.7.114 |
Related Weaknesses (CWE)
References
- http://shtaoism.com/Broken Link
- https://gist.github.com/Tsq741/a16015209fa8728d505c4f82b4f518cdThird Party Advisory
- http://shtaoism.com/Broken Link
- https://gist.github.com/Tsq741/a16015209fa8728d505c4f82b4f518cdThird Party Advisory
FAQ
What is CVE-2024-35375?
CVE-2024-35375 is a vulnerability with a CVSS score of 9.8 (CRITICAL). There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS
How severe is CVE-2024-35375?
CVE-2024-35375 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-35375?
Check the references section above for vendor advisories and patch information. Affected products include: Dedecms Dedecms.