Impact
An attacker can send a crafted HTTP request to the file_manage_control.php component of Dede CMS version 5.7.118, passing a malicious value in the str parameter. Because the application does not validate this value, it interprets the string as an arbitrary file path and reads the requested content. The result is the remote disclosure of sensitive data stored on the server. The flaw represents an information‑disclosure weakness (CWE‑200), allowing attackers to compromise confidentiality with minimal effort.
Affected Systems
The affected product is Dede CMS version 5.7.118. Any deployment that exposes the file_manage_control.php endpoint to users without proper authorization is vulnerable. No other versions or vendor products are listed in the available data.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1 % suggests a low probability of exploitation at the time of analysis. It is listed in no CISA KEV catalog. The likely attack vector is a web‑based HTTP request to the exposed endpoint, and based on the description it is inferred that the vulnerability can be exploited without authentication. Because the flaw allows arbitrary file reads, the potential impact on confidentiality is significant, and the difficulty of exploitation is low, resulting in a high‑risk information‑disclosure scenario.
OpenCVE Enrichment