PT-2026-45818 · Undefined · Undefined
R21Z20
·
Published
2026-06-02
·
Updated
2026-06-02
·
CVE-2026-10607
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
Fix
SQL injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Undefined