First published: Mon Jul 10 2023(Updated: )
A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233371.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | =5.7.109 | |
=5.7.109 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-3578 is critical (9.8 out of 10).
The affected software version of CVE-2023-3578 is DedeCMS 5.7.109.
Server-side request forgery (SSRF) is a vulnerability that allows an attacker to make unauthorized requests on behalf of a server.
To fix CVE-2023-3578, it is recommended to update DedeCMS to a version that is not affected by the vulnerability.
The Common Weakness Enumeration (CWE) ID of CVE-2023-3578 is CWE-918.