PT-2026-45819 · Dedecms · Dedecms
R21Z20
·
Published
2026-06-02
·
Updated
2026-06-04
·
CVE-2026-10608
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DedeCMS version 5.7.88
Description
A security flaw exists in the
RemoveXSS() function within the '/plus/carbuyaction.php' file. Remote attackers can perform SQL injection, which is a technique used to manipulate a database by inserting malicious SQL code into a query, by manipulating the postname and des arguments.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the '/plus/carbuyaction.php' file or avoid using the
postname and des arguments in that endpoint.Exploit
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dedecms