CVE-2024-11138 Information
Nov 14, 2024
cve
Description
A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_add.php. The manipulation of the argument logoimg leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Reference
https://vuldb.com/?id.283977 https://vuldb.com/?ctiid.283977 https://vuldb.com/?submit.441900 https://github.com/falling-snow1/cve1/blob/main/DedeCMS%20V5.7.116%20has%20Remote%20Code%20Excute%20vulnerability.md
Share on: