Executive brief
DeDeCMS is a content management system used to manage website content and media. A flaw in the media upload functionality allows attackers to upload files without proper restrictions, potentially enabling them to inject malicious content or gain unauthorized access to the system.
Technical details
An unrestricted file upload vulnerability exists in DeDeCMS 3 within the /include/dialog/select_media_post.php file. The vulnerability is triggered by manipulation of the uploadfile parameter, which fails to enforce adequate validation on uploaded files. The attack is remotely exploitable and does not require authentication. An attacker can leverage this to upload arbitrary files to the server, which may lead to remote code execution, malware injection, or other forms of system compromise.
Affected products
- DeDeCMS DeDeCMS 3
Timeline
- 2026-08-20: disclosed