Record summary

CVE-2018-7700 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHDedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code ExecutionCVSS 8.8

DedeCMS 5.7SP2 is susceptible to cross-site request forgery with a corresponding impact of arbitrary code execution because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

Impact

Successful exploitation of these vulnerabilities can lead to unauthorized actions performed on behalf of the user and execution of arbitrary code.

Remediation

Apply the latest security patches and update to a newer version of DedeCMS.

WeaknessesCWE-352
Authorspikpikcu
Template tagscvecve2018dedecmsrcevkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:dedecms:dedecms:5.7:*:*:*:*:*:*:*
Shodan: http.html:"dedecms"
Shodan: cpe:"cpe:2.3:a:dedecms:dedecms"
FOFA: body="dedecms"
FOFA: app="dedecms"

Source: ProjectDiscovery

References

2