DedeCMS
cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*
- 5.7.118
A code injection vulnerability has been identified in DedeCMS version 5.7.118, specifically within the Column Management feature. The issue arises in an unknown function of the file '/plus/search.php', where manipulation of the 'Column Name' argument allows for remote code execution. The vulnerability has been publicly disclosed and could be exploited by attackers.
Exploitation of this vulnerability allows for remote code execution on the server where DedeCMS is installed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.