Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media upload functionality. Attackers can exploit the file u…
High CVSS 8.8
Summary
Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload process by crafting a PHP shell with a command execution form to gain system access through the uploaded file.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.dotclear.org/explore/repos Broken Link
- https://github.com/dotclear/dotclear/archive/refs/heads/master.zip Product
- https://www.exploit-db.com/exploits/52037 Exploit
- https://www.vulncheck.com/advisories/dotclear-remote-code-execution-via-authenticated-file-upload Third Party Advisory
- https://github.com/dotclear/dotclear/archive/refs/heads/master.zip Product
Timeline
- nvd_ingest NVD