CVE-2024-6940

MEDIUM

DedeCMS 5.7.114 - Remote Code Injection in article_template_rand.php

Title source: llm
STIX 2.1

Description

A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-271995. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Third Party Advisory vdb-entry
https://vuldb.com/?id.271995
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.271995
Third Party Advisory third-party-advisory
https://vuldb.com/?submit.372810

Scores

CVSS v3 4.7
EPSS 0.0009
EPSS Percentile 25.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (1)
dedecms/dedecms 5.7.112
Published Jul 21, 2024
Tracked Since Feb 18, 2026