Vulnerability Description
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dedecms | Dedecms | <= 5.7.106 |
Related Weaknesses (CWE)
References
- https://srpopty.github.io/2023/02/27/DedeCMS-V5.7.160-Backend-SQLi-story/ExploitThird Party Advisory
- https://srpopty.github.io/2023/02/27/DedeCMS-V5.7.160-Backend-SQLi-story/ExploitThird Party Advisory
FAQ
What is CVE-2023-27709?
CVE-2023-27709 is a vulnerability with a CVSS score of 7.2 (HIGH). SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.
How severe is CVE-2023-27709?
CVE-2023-27709 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-27709?
Check the references section above for vendor advisories and patch information. Affected products include: Dedecms Dedecms.