CVE-2020-18917: CSRF
Published Aug 24, 2021
·Updated
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
Affected Software
1 affected component
DedeCMS Dedecms=5.7-sp2
Event History
Aug 24, 2021
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
Description
Frequently Asked Questions
1
What is CVE-2020-18917?
CVE-2020-18917 is a vulnerability in the plus/search.php component of DedeCMS 5.7 SP2 that allows remote attackers to execute arbitrary PHP code.
2
How severe is CVE-2020-18917?
CVE-2020-18917 has a severity rating of 8.8 (high).
3
What software is affected by CVE-2020-18917?
DedeCMS 5.7 SP2 is affected by CVE-2020-18917.
4
How can the CVE-2020-18917 vulnerability be exploited?
CVE-2020-18917 can be exploited by sending malicious input through the typename parameter in the plus/search.php component of DedeCMS 5.7 SP2.
5
Is there a fix available for CVE-2020-18917?
At the time of writing, there is no known fix for CVE-2020-18917. It is recommended to follow the provided reference for any official updates or patches.