CVE-2018-16785

HIGH

dedecms V5.7 SP2 - XML Injection

Title source: llm
STIX 2.1

Description

XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/ky-j/dedecms/issues/4

Scores

CVSS v3 8.8
EPSS 0.0192
EPSS Percentile 77.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-91
Status published
Products (1)
dedecms/dedecms 5.7 sp2
Published Sep 19, 2018
Tracked Since Feb 18, 2026