Impact
The vulnerability exists in DeDeCMS 53_1_UTF8 within the endpoint '/plus/advancedsearch.php' and allows attackers to manipulate the sql argument to inject arbitrary SQL through improper input handling, as indicated by CWE-74 and CWE-89. The flaw does not require local access or advanced privileges; an attacker can supply crafted input from the internet to gain database access and potentially extract or modify sensitive data.
Affected Systems
Systems running DeDeCMS 53_1_UTF8 are impacted. The specific code in the advancedsearch.php file is responsible for the vulnerability. No other product versions are mentioned as affected, but any deployment that includes the vulnerable file should be inspected.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. The EPSS score is not available, providing no quantitative exploitation likelihood, yet the fact that the exploit is publicly disclosed and can be launched remotely raises concern. The vulnerability is not listed in CISA’s KEV catalog, but the remote nature of the attack, combined with the absence of an immediate authentication requirement, makes it suitable for automated attacks.
OpenCVE Enrichment