CVE-2018-7700: CSRF
Published Mar 27, 2018
·Updated
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tagtestaction.php request can specify a runphp field in conjunction with PHP code.
Affected Software
1 affected component
DedeCMS Dedecms=5.7
Event History
Mar 27, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7700?
CVE-2018-7700 has a high severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2018-7700?
To fix CVE-2018-7700, update to a patched version of DedeCMS or implement CSRF protections in your application.
3
What software is affected by CVE-2018-7700?
CVE-2018-7700 affects DedeCMS version 5.7.
4
What type of vulnerability is CVE-2018-7700?
CVE-2018-7700 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What impact can CVE-2018-7700 have on my website?
CVE-2018-7700 can lead to arbitrary code execution, allowing attackers to execute malicious code on your server.