CVE-2018-9134

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
30/03/2018
Last modified:
23/04/2018

Description

file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dedecms:dedecms:5.7:*:*:*:*:*:*:*