CVE-2018-7700

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
27/03/2018
Last modified:
19/04/2018

Description

DedeCMS 5.7 has CSRF with an impact of arbitrary code execution, because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dedecms:dedecms:5.7:*:*:*:*:*:*:*