A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233371.
References
Link | Resource |
---|---|
https://github.com/nightcloudos/cve/blob/main/SSRF.md | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.233371 | Permissions Required Third Party Advisory |
https://vuldb.com/?id.233371 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-07-10 16:15
Updated : 2024-05-17 02:27
NVD link : CVE-2023-3578
Mitre link : CVE-2023-3578
CVE.ORG link : CVE-2023-3578
JSON object : View
Products Affected
dedecms
- dedecms
CWE
CWE-918
Server-Side Request Forgery (SSRF)