CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-35375: There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS

Description

There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS

Classification

CVE ID: CVE-2024-35375

Affected Products

Vendor: n/a

Product: n/a

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.98% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

http://shtaoism.com/
https://gist.github.com/Tsq741/a16015209fa8728d505c4f82b4f518cd

Timeline