First published: Tue Mar 27 2018(Updated: )
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 | =5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7700 has a high severity due to the potential for arbitrary code execution.
To fix CVE-2018-7700, update to a patched version of DedeCMS or implement CSRF protections in your application.
CVE-2018-7700 affects DedeCMS version 5.7.
CVE-2018-7700 is a Cross-Site Request Forgery (CSRF) vulnerability.
CVE-2018-7700 can lead to arbitrary code execution, allowing attackers to execute malicious code on your server.