SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-26T18:47:55.078Z
Reserved: 2023-03-05T00:00:00.000Z
Link: CVE-2023-27709

Updated: 2024-08-02T12:16:36.932Z

Status : Modified
Published: 2023-03-16T15:15:10.607
Modified: 2025-02-26T19:15:18.810
Link: CVE-2023-27709

No data.