CVE-2024-35375

CRITICAL

dedecms 5.7.114 - Unauthenticated Arbitrary File Upload via Media Add Page

Title source: llm
STIX 2.1

Description

There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0047
EPSS Percentile 36.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
dedecms/dedecms 5.7.114
Published May 23, 2024
Tracked Since Feb 18, 2026