PT-2026-69294 · Dedecms · Dedecms
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
DedeCMS versions prior to 5.7.119 UTF8SP2
Description
A file inclusion issue exists within the Installation Wizard component. The flaw is located in the
4 Setup() function of the install/index.php file. This allows a remote attacker to include files through a high-complexity attack that is difficult to execute.Recommendations
Update DedeCMS to a version newer than 5.7.118 UTF8SP2.
As a temporary mitigation, restrict access to the
install/index.php file or disable the Installation Wizard component.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dedecms