SQL Injection Vulnerability in DedeCMS from DedeSoft
CVE-2023-27707
7.2HIGH
What is CVE-2023-27707?
DedeCMS versions 5.7.106 and 5.7.160 are affected by a SQL injection vulnerability that can be exploited via the rank_* parameter in the /dede/group_store.php endpoint. This flaw allows remote attackers to execute arbitrary code, posing significant risks to data integrity and web application security. Proper sanitization and validation of user inputs are essential to mitigate the potential impact of this vulnerability.