CVE-2025-5137: DedeCMS Incomplete Fix CVE-2018-9175 sys_verifies.php code injection
A vulnerability was found in DedeCMS 5.7.117. It has been classified as critical. Affected is an unknown function of the file dede/sysverifies.php?action=getfiles of the component Incomplete Fix CVE-2018-9175. The manipulation of the argument refiles leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5137?
CVE-2025-5137 has been classified as critical due to the potential for code injection.
How do I fix CVE-2025-5137?
To fix CVE-2025-5137, update DedeCMS to the latest version that addresses this vulnerability.
What components of DedeCMS are affected by CVE-2025-5137?
CVE-2025-5137 specifically affects the file dede/sys_verifies.php in DedeCMS.
What type of vulnerability is CVE-2025-5137?
CVE-2025-5137 is a code injection vulnerability resulting from an incomplete fix of a previous vulnerability.
What is the impact of exploiting CVE-2025-5137?
Exploiting CVE-2025-5137 can allow an attacker to execute arbitrary code on the affected system.