Impact
The vulnerability is located in the base64_decode function used by DedeCMS download.php. When the Link argument is manipulated, the function processes a base64‑encoded payload that causes the server to issue an HTTP request to an arbitrary URL. This server‑side request forgery (SSRF) can be triggered by remote attackers, allowing them to reach internal or external network resources, perform data exfiltration, or abuse the server to attack other systems.
Affected Systems
The flaw affects DedeCMS version 5.7.88, as identified for the plus/download.php script. Users running that version, or any unpatched derivative, are exposed. No other DedeCMS versions or products are explicitly listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the EPSS score is not available, but an exploit has been published. Because the vulnerability can be triggered purely through web requests, the attack vector is remote over the internet. The flaw does not compromise local system integrity directly but provides the attacker a covert channel to the server’s outbound network. No KEV listing indicates it is not currently a catalogued known exploitation program, but the presence of an active exploit means it should be treated as a potential threat.
OpenCVE Enrichment