Record summary

CVE-2023-2059 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issue is some unknown functionality of the file uploads/include/dialog/select_templets.php. The manipulation leads to path traversal: '..\filedir'. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-225944.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 23, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

DedeCMS

CVE List5.7.87affected

Nuclei templates

1
ProjectDiscoveryMEDIUMDedeCMS 5.7.87 - Directory TraversalCVSS 5.3

Directory traversal vulnerability in DedeCMS 5.7.87 allows reading sensitive files via the $activepath parameter.

Impact

Unauthenticated attackers can exploit directory traversal through the activepath parameter in select_templets.php to read sensitive DedeCMS configuration files and source code.

Remediation

Update DedeCMS to a version newer than 5.7.87 that properly validates and sanitizes the activepath parameter in select_templets.php.

WeaknessesCWE-28
Authorspussycat0x
Template tagscvecve2023dedecmslfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:dedecms:dedecms:5.7.87:*:*:*:*:*:*:*
Shodan: http.html:"dedecms"
Shodan: cpe:"cpe:2.3:a:dedecms:dedecms"
FOFA: app="DedeCMS"
FOFA: app="dedecms"
FOFA: body="dedecms"

Source: ProjectDiscovery

References

4