Executive brief
DedeCMS, a popular content management system, contains a security flaw in its download handling component. An attacker can exploit this to make the server perform unauthorized requests to internal or external systems. This could lead to the exposure of internal network information or unauthorized access to internal services.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in DedeCMS 5.7.88 within the /plus/download.php script. The vulnerability is located in the handling of the 'Link' argument, which is processed by the base64_decode function when the 'open' parameter is set to 1. By providing a specially crafted, base64-encoded URL, a remote attacker with low privileges can force the server to initiate outbound requests. This can be used to scan internal networks, bypass firewalls, or interact with internal services that are not otherwise accessible from the internet. Public exploit code is reportedly available.
Affected products
- DedeCMS DedeCMS 5.7.88
Timeline
- 2026-06-02: advisory: NVD published the vulnerability record.
- 2026-06-02: disclosed: Vulnerability information and exploit details were made public.