CVE-2023-3578: DedeCMS co_do.php server-side request forgery
A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file codo.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233371.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3578?
The severity of CVE-2023-3578 is critical (9.8 out of 10).
What is the affected software version of CVE-2023-3578?
The affected software version of CVE-2023-3578 is DedeCMS 5.7.109.
What is server-side request forgery?
Server-side request forgery (SSRF) is a vulnerability that allows an attacker to make unauthorized requests on behalf of a server.
How can I fix CVE-2023-3578?
To fix CVE-2023-3578, it is recommended to update DedeCMS to a version that is not affected by the vulnerability.
What is the Common Weakness Enumeration (CWE) ID of CVE-2023-3578?
The Common Weakness Enumeration (CWE) ID of CVE-2023-3578 is CWE-918.