Executive brief
DedeCMS is a content management system used to publish and manage website content. A vulnerability in the plus/mytag_js.php file allows remote attackers to inject and execute arbitrary code through the aid parameter, potentially giving them full control of the website and underlying server.
Technical details
A code injection vulnerability exists in DedeCMS's plus/mytag_js.php file where the aid parameter is not properly sanitized before processing. An unauthenticated attacker can send a crafted request over the network to inject arbitrary code that will be executed server-side, resulting in remote code execution.
Affected products
- DedeCMS DedeCMS up to 5.7.118
Timeline
- 2026-09-20: disclosed