First published: Thu Mar 16 2023(Updated: )
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | <=5.7.106 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SQL injection vulnerability is CVE-2023-27709.
The affected software is DedeCMS version 5.7.106.
This vulnerability has a severity value of 7.2, which is categorized as high.
A remote attacker can exploit this vulnerability by sending malicious code through the rank_* parameter in the /dedestory_catalog.php endpoint.
Yes, it is recommended to update to a patched version of DedeCMS to mitigate the SQL injection vulnerability.