VYPR
High severity8.8NVD Advisory· Published Sep 28, 2023· Updated Jun 17, 2026

CVE-2023-43226

CVE-2023-43226

Description

An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.

Affected products

3
  • Dedecms/Dedecms3 versions
    cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:*range: <=5.7.111
    • (no CPE)
    • (no CPE)range: <=5.7.111

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.

CVE-2023-43226 · High · VYPR