Junglewise Threat Intelligence

CVE-2026-10607: DedeCMS SQL injection in flink.php

CVE-2026-10607 · Severity: high · CVSS 7.3 · Published 2026-06-02

Technologies: DedeCMS. Vendors: DedeCMS.

Executive brief

DedeCMS, a popular content management system, contains a security flaw in its link management component. An attacker can exploit this vulnerability to interfere with the website's database without needing a password. This could lead to unauthorized access to sensitive information, data modification, or disruption of the website's operations.

Technical details

A SQL injection vulnerability exists in DedeCMS version 5.7.88 within the 'dede_htmlspecialchars' function located in '/plus/flink.php'. The vulnerability is triggered by insufficient sanitization of the 'msg' parameter. A remote, unauthenticated attacker can exploit this by sending specially crafted network requests to the affected script. Successful exploitation allows for the execution of arbitrary SQL commands, potentially leading to data exfiltration or database manipulation. Public exploit code is reportedly available.

Affected products

  • DedeCMS DedeCMS 5.7.88

Timeline

  • 2026-06-02: disclosed: Initial vulnerability disclosure and NVD publication.

References

Related threats