PT-2022-27114 · Dedecmdv6 · Dedecmdv6

·

CVE-2022-44118

·

Published

2022-11-23

·

Updated

2025-04-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dedecmdv6 version 6.1.9
Description The issue allows for Remote Code Execution (RCE) via the file manage control.php endpoint.
Recommendations For dedecmdv6 version 6.1.9, consider restricting access to the file manage control.php endpoint until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-44118

Affected Products

Dedecmdv6