top of page
perceptive_background_267k.jpg

An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.

Published:

31 maart 2026 om 22:00:00

Alert date:

1 april 2026 om 20:03:08

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

A code execution vulnerability has been discovered in DedeCMS version 5.7.118. The vulnerability allows attackers to execute arbitrary code through crafted setup tag values during module upload processes. This represents a critical security flaw in the content management system that could lead to complete system compromise. Attackers can exploit this vulnerability by uploading malicious modules with specially crafted setup tags. The vulnerability affects the module upload functionality of the CMS. This could allow unauthorized code execution on affected systems running the vulnerable DedeCMS version.

Technical details

Mitigation steps:

Affected products:

DedeCMS

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page