PT-2026-45818 · Undefined · Undefined

R21Z20

·

Published

2026-06-02

·

Updated

2026-06-02

·

CVE-2026-10607

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

Fix

SQL injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-10607

Affected Products

Undefined