VYPR
Medium severity5.5NVD Advisory· Published Sep 17, 2023· Updated Jun 17, 2026

CVE-2023-5022

CVE-2023-5022

Description

A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this vulnerability is VDB-239863.

Affected products

3
  • Dedecms/Dedecms3 versions
    cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:*range: <=5.7.100
    • (no CPE)
    • (no CPE)range: <=5.7.100

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.