CVE-2024-9076
PoC largeAuthenticated OS Command Injection in DedeCMS article_string_mix.php
DedeCMS up to and including version 5.7.115 is vulnerable to OS command injection (CWE-77/CWE-78) in /dede/article_string_mix.php, where unvalidated input is passed to the operating system. The flaw is exploitable remotely, but per the CVSS 4.0 vector it requires high privileges, meaning an attacker must already hold authenticated, likely administrative, access to the CMS backend. Successful exploitation lets the attacker run arbitrary operating system commands on the web server with the privileges of the web application, though the CVSS 4.0 score of 5.1 (medium) indicates limited scope and low-severity impact on confidentiality, integrity, and availability. All DedeCMS deployments running 5.7.115 or earlier are affected, and a public proof-of-concept has been published on Gitee. The vendor was notified but did not respond, no fixed version is stated in the available data, and while the flaw is not yet in CISA KEV, EPSS assigns it a 20.8% probability of exploitation within 30 days (97th percentile).
What to do: Because no fixed version is specified in the available data and the vendor has not responded, restrict and monitor access to /dede/article_string_mix.php, limiting it to trusted administrative users only. Check web logs for unexpected requests or command metacharacters targeting that endpoint, and apply a WAF rule blocking shell metacharacters in parameters to that script as an interim mitigation. Watch the vendor's distribution channels for a patched release and upgrade beyond 5.7.115 as soon as a fix becomes available.
| DedeCMS | up to and including 5.7.115 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- dedecms
- Products
- dedecms
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.