CVE-2025-6335

MEDIUM

DedeCMS <5.7.2 - Command Injection

Title source: llm

Description

A vulnerability was found in DedeCMS up to 5.7.2 and classified as critical. This issue affects some unknown processing of the file /include/dedetag.class.php of the component Template Handler. The manipulation of the argument notes leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Exploits (1)

nomisec WORKING POC 6 stars
by jujubooom · poc
https://github.com/jujubooom/CVE-2025-6335

Scores

CVSS v3 4.7
EPSS 0.0017
EPSS Percentile 38.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-74 CWE-77
Status published

Affected Products (1)

dedecms/dedecms < 5.7.2

Timeline

Published Jun 20, 2025
Tracked Since Feb 18, 2026