'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2018-7700: Dedecms V5.7 Remote code execution
Severity:high
CVE ID:CVE-2018-7700
| Descripiton:
|
Desdev DedeCMS (Dream Weaving Content Management System) is a set of open source PHP website content management system (CMS) that integrates content publishing, editing, management and retrieval from China Zhuozhuo Network (Desdev) Technology Co., Ltd. There is a cross-site request forgery vulnerability in Desdev DedeCMS 5.7 version. A remote attacker can use this vulnerability to execute arbitrary code by sending the ‘partcode’ parameter to the tag_test_action.php file. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.