Impact
DedeCMS version 5.7.118 contains a code injection flaw in the /plus/search.php file of the Column Management component. By manipulating the Column Name parameter, an attacker can inject arbitrary PHP code, which is then executed on the web server. This weakness is classified as CWE‑74 and CWE‑94 and allows a remote attacker to run malicious code with the privileges of the web application.
Affected Systems
The vulnerable product is DedeCMS version 5.7.118. No other releases are explicitly listed as impacted, so the risk is confined to that specific build unless similar code paths exist in earlier or later versions.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the EPSS score of less than 1% suggests a low expected exploitation frequency. The vulnerability is not listed in the CISA KEV catalog. However, an exploit has been publicly released, so a remote attacker who can reach the Column Name field can construct a crafted request to execute arbitrary code on the server. While the statistical likelihood remains low, the presence of a public exploit and the remote nature of the attack elevate the risk to a priority tactical concern.
OpenCVE Enrichment