First published: Fri Sep 29 2023(Updated: )
A vulnerability, which was classified as critical, was found in DedeBIZ 6.2. This affects an unknown part of the file /src/admin/tags_main.php. The manipulation of the argument ids leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240879.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 | =6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5266 is high with a score of 8.8.
DedeBIZ version 6.2 is affected by CVE-2023-5266.
The vulnerability in CVE-2023-5266 occurs due to SQL injection in the /src/admin/tags_main.php file.
Yes, this vulnerability can be exploited remotely.
There is currently no known fix available for CVE-2023-5266. It is recommended to update to a newer version of DedeBIZ when one becomes available.