CVE-2023-2928
Description
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230083.
NVD
Severity: HIGH
CVE ID: CVE-2023-2928
CVSS Score: 8.8
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
VulDB
Severity: MEDIUM
CVE ID: CVE-2023-2928
CVSS Score: 6.3
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Proof Of Concept
CN016
DedeCMS文件包含漏洞导致后台getshell(CVE-2023-2928)复现
Refrence: GitHub