github.com
https://github.com/QianGeG/CVE/issues/14 CVE-2024-35510
CRITICAL
Record summary
CVE-2024-35510 has a selected CVSS score of 9.8 (critical).
Description
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 7, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dedecmsBrowse dedecms / dedecmsDefault status: unknown | CVE List | 5.7.114 | affected |