CVE-2023-27709: SQL Injection
Published Mar 16, 2023
·Updated
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank parameter in the /dedestorycatalog.php endpoint.
Affected Software
1 affected component
DedeCMS Dedecms<=5.7.106
Event History
Mar 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this SQL injection vulnerability?
The vulnerability ID for this SQL injection vulnerability is CVE-2023-27709.
2
What is the affected software?
The affected software is DedeCMS version 5.7.106.
3
How severe is this vulnerability?
This vulnerability has a severity value of 7.2, which is categorized as high.
4
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by sending malicious code through the rank_* parameter in the /dedestory_catalog.php endpoint.
5
Is there a fix for this vulnerability?
Yes, it is recommended to update to a patched version of DedeCMS to mitigate the SQL injection vulnerability.