Impact
The vulnerability is located in an unspecified helper function within the plus/mytag_js.php file of DedeCMS. By manipulating the aid parameter, an attacker can inject code that the system will execute, effectively allowing arbitrary code execution on the web server.
Affected Systems
DedeCMS (versions up to and including 5.7.118).
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the exploit can be launched remotely by sending a crafted request containing a malicious aid value. EPSS data are not available, and the vulnerability is not listed in CISA’s KEV catalog. However, the public availability of an exploit means that attackers can readily target vulnerable installations.
OpenCVE Enrichment