CVE-2018-12045: Dedecms

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.

Affected products

  • Dedecms Dedecms: before 5.7 (fixed in 5.7); version 5.7 only

Published 2018-06-08. Last modified 2026-06-17.