CVE-2018-10375 is a critical file upload vulnerability in DedeCMS V5.7 SP2, specifically within the /include/helpers/upload.helper.php component. Attackers can exploit this by uploading malicious PHP code disguised as a JPEG image, bypassing content-type checks. This unauthenticated remote code execution vulnerability carries a CVSS score of 9.8, indicating severe impacts on confidentiality, integrity, and availability. While no public exploits like Metasploit or ExploitDB entries are noted, the vulnerability has garnered significant community discussion, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.7CPE matchmatch criteria | cpe:2.3:a:dedecms:dedecms:5.7:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.