ZeroHour

CVE-2024-9076

PoC large

Authenticated OS Command Injection in DedeCMS article_string_mix.php

CVSS 4.0
5.1 medium
EPSS
21%p97
Published
()
Modified
AI analysis

DedeCMS up to and including version 5.7.115 is vulnerable to OS command injection (CWE-77/CWE-78) in /dede/article_string_mix.php, where unvalidated input is passed to the operating system. The flaw is exploitable remotely, but per the CVSS 4.0 vector it requires high privileges, meaning an attacker must already hold authenticated, likely administrative, access to the CMS backend. Successful exploitation lets the attacker run arbitrary operating system commands on the web server with the privileges of the web application, though the CVSS 4.0 score of 5.1 (medium) indicates limited scope and low-severity impact on confidentiality, integrity, and availability. All DedeCMS deployments running 5.7.115 or earlier are affected, and a public proof-of-concept has been published on Gitee. The vendor was notified but did not respond, no fixed version is stated in the available data, and while the flaw is not yet in CISA KEV, EPSS assigns it a 20.8% probability of exploitation within 30 days (97th percentile).

What to do: Because no fixed version is specified in the available data and the vendor has not responded, restrict and monitor access to /dede/article_string_mix.php, limiting it to trusted administrative users only. Check web logs for unexpected requests or command metacharacters targeting that endpoint, and apply a WAF rule blocking shell metacharacters in parameters to that script as an interim mitigation. Watch the vendor's distribution channels for a patched release and upgrade beyond 5.7.115 as soon as a fix becomes available.

Affected
DedeCMSup to and including 5.7.115
Estimated exposure
largelikely on the order of tens of thousands to hundreds of thousands of sites (no authoritative install count in the data) — DedeCMS is a long-popular CMS widely deployed in China with broad historical internet exposure, suggesting a large install base, but the provided data contains no active-install or scan counts, so this is an order-of-magnitude estimate;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors
dedecms
Products
dedecms
Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.