Show filters
123 Total Results
Displaying 31-40 of 123
Sort by:
Attacker Value
Unknown
CVE-2024-2820
Disclosure Date: March 22, 2024 (last updated January 16, 2025)
A vulnerability classified as problematic was found in DedeCMS 5.7. Affected by this vulnerability is an unknown functionality of the file /src/dede/baidunews.php. The manipulation of the argument filename leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257707. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-22895
Disclosure Date: January 22, 2024 (last updated January 27, 2024)
DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.
0
Attacker Value
Unknown
CVE-2023-7212
Disclosure Date: January 07, 2024 (last updated January 12, 2024)
A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component Backend. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249768. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-49494
Disclosure Date: December 11, 2023 (last updated December 14, 2023)
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.
0
Attacker Value
Unknown
CVE-2023-49493
Disclosure Date: December 07, 2023 (last updated December 13, 2023)
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php.
0
Attacker Value
Unknown
CVE-2023-49492
Disclosure Date: December 07, 2023 (last updated December 13, 2023)
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.
0
Attacker Value
Unknown
CVE-2023-43275
Disclosure Date: November 16, 2023 (last updated November 21, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.
0
Attacker Value
Unknown
CVE-2023-48068
Disclosure Date: November 13, 2023 (last updated November 17, 2023)
DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php.
0
Attacker Value
Unknown
CVE-2023-5301
Disclosure Date: September 30, 2023 (last updated October 08, 2023)
A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. The manipulation of the argument albumUploadFiles leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-240940.
0
Attacker Value
Unknown
CVE-2023-43226
Disclosure Date: September 28, 2023 (last updated October 08, 2023)
An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
0