Executive brief
DedeCMS, a popular content management system, contains a security flaw in its Album Publishing Feature. An attacker with high-level administrative privileges can exploit this to manipulate file paths during the extraction of ZIP archives. This could allow an attacker to write files to unauthorized locations on the server, potentially leading to remote code execution and a full compromise of the website.
Technical details
A path traversal vulnerability (CWE-22) exists in DedeCMS 5.7.118 within the ExtractFile function of include/zip.class.php. The vulnerability is located in the Album Publishing Feature and is triggered by insufficient validation of the 'filename' argument during ZIP file extraction. A remote attacker with high privileges (PR:H) can provide a specially crafted filename to traverse directories and potentially achieve Remote Code Execution (RCE) by overwriting or creating PHP files in the web root. A public exploit has been released.
Affected products
- DedeCMS DedeCMS 5.7.118
Timeline
- 2026-07-14: advisory: NVD publication date
- 2026-07-14: disclosed: Public exploit released via GitHub repository