CVE-2024-7906

MEDIUM

Dedebiz - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

A vulnerability classified as critical was found in DedeBIZ 6.3.0. This vulnerability affects the function get_mime_type of the file /admin/dialog/select_images_post.php of the component Attachment Settings. The manipulation of the argument upload leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.275032
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.275032
Third Party Advisory third-party-advisory
https://vuldb.com/?submit.388363

Scores

CVSS v3 6.3
EPSS 0.0014
EPSS Percentile 33.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
dedebiz/dedebiz 6.3.0
Published Aug 18, 2024
Tracked Since Feb 18, 2026