CVE-2023-4747: DedeCMS tags.php sql injection
A vulnerability classified as critical was found in DedeCMS 5.7.110. This vulnerability affects unknown code of the file /uploads/tags.php. The manipulation of the argument tagalias leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238636.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4747?
The severity of CVE-2023-4747 is critical, with a CVSS score of 9.8.
What is the affected software of CVE-2023-4747?
The affected software of CVE-2023-4747 is DedeCMS 5.7.110.
How does CVE-2023-4747 affect the software?
CVE-2023-4747 affects the software by allowing remote attackers to initiate SQL injection attacks through the manipulation of the tag_alias argument in the file /uploads/tags.php.
Is there a publicly available exploit for CVE-2023-4747?
Yes, there is a publicly available exploit for CVE-2023-4747.
How can I fix CVE-2023-4747?
To fix CVE-2023-4747, it is recommended to apply the latest security patches or updates provided by the DedeCMS vendor.