CVE-2018-7700
dedecms dedecms Cross-Site Request Forgery (CSRF)
Record summary
CVE-2018-7700 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 13, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dedecmsBrowse dedecms / dedecms | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHDedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code ExecutionCVSS 8.8
DedeCMS 5.7SP2 is susceptible to cross-site request forgery with a corresponding impact of arbitrary code execution because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.
Impact
Successful exploitation of these vulnerabilities can lead to unauthorized actions performed on behalf of the user and execution of arbitrary code.
Remediation
Apply the latest security patches and update to a newer version of DedeCMS.
Source: ProjectDiscovery