CRITICAL🇵🇱 Wersja polska

CVE-2024-33749

CVSS 9.1v3.1pub. 2024-05-06upd. 2025-04-01

DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.

🤖 AI Analysis
How it works

The vulnerability results from improper authorization verification in the mail_file_manage.php file — the script does not properly check whether the requesting user has the right to perform the file deletion operation. An attacker can send a specially crafted network request pointing to any file on the server and cause its deletion. Due to the network vector (AV:N), lack of authentication requirement (PR:N), and no user interaction (UI:N), the attack is possible remotely without any credentials.

Impact

An attacker can permanently delete any files accessible from the web server process, which may lead to data integrity loss, destruction of application configuration, or complete service disruption (denial of service).

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references. As an interim workaround, it is recommended to restrict access to the mail_file_manage.php file at the web server level or application firewall (WAF) to trusted IP addresses.

Who is affected

DedeCMS version V5.7.114

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Dedecms

    APP
    Dedecms
    5.7.114
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-30643CRITICAL9.8PL ✓same product

DedeCMS 5.7.118 — zdalne wykonanie kodu przez upload modułu (RCE)

CVE-2026-30694CRITICAL9.8PL ✓same product

RCE w DedeCMS poprzez komponent array_filter

CVE-2024-35510CRITICAL9.8PL ✓same product

DedeCMS – arbitrary file upload umożliwiający RCE

CVE-2024-35375CRITICAL9.8PL ✓same product

DedeCMS 5.7.114 — arbitrary file upload w panelu administracyjnym

CVE-2024-29661CRITICAL9.8PL ✓same product

Krytyczne RCE przez File Upload w DedeCMS v5.7