DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.
The vulnerability results from improper authorization verification in the mail_file_manage.php file — the script does not properly check whether the requesting user has the right to perform the file deletion operation. An attacker can send a specially crafted network request pointing to any file on the server and cause its deletion. Due to the network vector (AV:N), lack of authentication requirement (PR:N), and no user interaction (UI:N), the attack is possible remotely without any credentials.
An attacker can permanently delete any files accessible from the web server process, which may lead to data integrity loss, destruction of application configuration, or complete service disruption (denial of service).
Patches available from the vendor should be applied in accordance with the references. As an interim workaround, it is recommended to restrict access to the mail_file_manage.php file at the web server level or application firewall (WAF) to trusted IP addresses.
DedeCMS version V5.7.114
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HDedecms
APPDedecms5.7.114
Related vulnerabilities
DedeCMS 5.7.118 — zdalne wykonanie kodu przez upload modułu (RCE)
RCE w DedeCMS poprzez komponent array_filter
DedeCMS – arbitrary file upload umożliwiający RCE
DedeCMS 5.7.114 — arbitrary file upload w panelu administracyjnym
Krytyczne RCE przez File Upload w DedeCMS v5.7