CVE-2023-27707: SQL Injection
Published Mar 16, 2023
·Updated
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank parameter in the /dede/groupstore.php endpoint.
Affected Software
1 affected component
DedeCMS Dedecms<=5.7.106
Event History
Mar 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-27707.
2
What is the severity of CVE-2023-27707?
The severity of CVE-2023-27707 is high, with a severity value of 7.2.
3
What is the affected software for CVE-2023-27707?
The affected software for CVE-2023-27707 is DedeCMS v.5.7.106.
4
How does the attacker exploit CVE-2023-27707?
The attacker exploits CVE-2023-27707 by injecting SQL code via the rank_* parameter in the /dede/group_store.php endpoint.
5
Is there a fix available for CVE-2023-27707?
Yes, a fix is available for CVE-2023-27707. It is recommended to update to a patched version of DedeCMS to mitigate this vulnerability.