CVE-2019-8362

HIGH

Dedecms < 5.7 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1.jpg.php" (because input validation only checks that .jpg, .png, or .gif is present as a substring, and does not otherwise check the file name or content).

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0021
EPSS Percentile 42.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-434
Status published
Products (2)
dedecms/dedecms 5.7 (3 CPE variants)
dedecms/dedecms < 5.7
Published Feb 16, 2019
Tracked Since Feb 18, 2026