Learn about CVE-2018-12045, a vulnerability in DedeCMS allowing arbitrary file uploads, including .php files. Find mitigation steps and long-term security practices here.
DedeCMS up to version 5.7SP2 has a vulnerability that allows users to upload malicious files, including .php files, through specific pages.
Understanding CVE-2018-12045
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter.
What is CVE-2018-12045?
This CVE identifies a vulnerability in DedeCMS that permits users to upload any file, including malicious .php files, through a specific page and request.
The Impact of CVE-2018-12045
Technical Details of CVE-2018-12045
DedeCMS version 5.7SP2 is susceptible to an arbitrary file upload vulnerability through specific page requests.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take: