DesDev DedeCMS(织梦内容管理系统)是中国卓卓(DesDev)公司的一套基于PHP的开源内容管理系统(CMS)。该系统具有内容发布、内容管理、内容编辑和内容检索等功能。 DesDev DedeCMS 5.7.117版本存在注入漏洞,该漏洞源于对文件dede/sys_verifies.php?action=getfiles中参数refiles的错误操作导致代码注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | DedeCMS | 5.7.117 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-5150 | 6.3 MEDIUM | docarray Web API torch_dataset.py __getitem__ prototype pollution |
| CVE-2025-5149 | 5.6 MEDIUM | WCMS Login getallcon getMemberByUid improper authentication |
| CVE-2025-5139 | 5.6 MEDIUM | Qualitor Office 365-type Connection testaConexaoOffice365.php command injection |
| CVE-2025-5153 | 3.5 LOW | CMS Made Simple Design Manager Module cross site scripting |
| CVE-2025-5138 | 3.5 LOW | Bitwarden PDF File cross site scripting |
| CVE-2025-5154 | 2.3 LOW | PhonePe App SQLite Database databases cleartext storage in a file or on disk |
No comments yet