DedeCMS 5.7SP2 is susceptible to cross-site request forgery with a corresponding impact of arbitrary code execution because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.
id: CVE-2018-7700
info:
name: DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution
...