PT-2022-27876 · Dedecms · Dedecms

Yinfei6

·

Published

2022-12-27

·

Updated

2023-01-06

·

CVE-2022-46442

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dedecms versions prior to V5.7.103
Description The issue is related to SQL Injection. In the sys sql n query.php file, there are no restrictions on the SQL query, which can be exploited.
Recommendations For dedecms versions prior to V5.7.103, update to version V5.7.103 or later to resolve the issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-46442

Affected Products

Dedecms