top of page
perceptive_background_267k.jpg

A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler.…

Published:

1 June 2026 at 22:00:00

Alert date:

2 June 2026 at 18:03:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

A SQL injection vulnerability has been identified in DedeCMS version 5.7.88. The vulnerability exists in the TrimMsg function within the /plus/feedback.php file of the Feedback Handler component. Attackers can exploit this vulnerability by manipulating the 'msg' argument to execute SQL injection attacks. The vulnerability can be exploited remotely, making it particularly dangerous. The exploit has been publicly disclosed and is available for use, increasing the risk of active exploitation. This affects the content management system's feedback functionality and could allow unauthorized database access.

Technical details

Mitigation steps:

Affected products:

DedeCMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page