HIGH
file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution
Published Mar 30, 2018
8.8
HIGHCVSS 3.0
EPSS 0.71%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.