Dedecms 5.71sp1 and earlier contain a URL redirect caused by a logic error that does not properly validate GET request input, letting attackers redirect users to arbitrary URLs, exploit requires sending crafted GET requests.
id: CVE-2024-57241
info:
name: DedeCMS - Open Redirect via download.php
author: 0x_Akoko
seve
...