CVE-2024-11138 - CERT CVE
ID CVE-2024-11138
Sažetak A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_add.php. The manipulation of the argument logoimg leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Reference
CVSS
Base: 3.3
Impact: 2.9
Exploitability:6.4
Pristup
VektorSloženostAutentikacija
NETWORK LOW MULTIPLE
Impact
PovjerljivostCjelovitostDostupnost
NONE NONE PARTIAL
CVSS vektor AV:N/AC:L/Au:M/C:N/I:N/A:P
Zadnje važnije ažuriranje 13-11-2024 - 17:01
Objavljeno 12-11-2024 - 18:15