


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of th…
Published:
1 June 2026 at 22:00:00
Alert date:
2 June 2026 at 21:03:34
Source:
nvd.nist.gov
Web Technologies
A SQL injection vulnerability was identified in DedeCMS version 5.7.88. The vulnerability affects the dede_htmlspecialchars function in the /plus/flink.php file, where manipulation of the msg argument leads to SQL injection. The attack can be initiated remotely and exploits are publicly available, making this a high-risk vulnerability for affected systems.
Technical details
Mitigation steps:
Affected products:
DedeCMS
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-10607
https://vuldb.com/cve/CVE-2026-10607
https://vuldb.com/submit/829414
https://vuldb.com/vuln/367914
https://vuldb.com/vuln/367914/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
