Vulnerabilities > CVE-2023-5022 - Absolute Path Traversal vulnerability in Dedecms

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
dedecms
CWE-36

Summary

A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this vulnerability is VDB-239863.

Vulnerable Configurations

Part Description Count
Application
Dedecms
82

Common Weakness Enumeration (CWE)