Cross-Site Request Forgery in DedeCMS Affects Version 5.7
CVE-2024-28673
8.8HIGH
What is CVE-2024-28673?
DedeCMS version 5.7 has been found to have a Cross-Site Request Forgery (CSRF) flaw that can be exploited through the endpoint /dede/mychannel_edit.php. This vulnerability allows unauthorized commands to be executed on behalf of a user without their consent, potentially compromising the security of the affected site. Attackers can leverage this vulnerability to manipulate user actions, which may result in unauthorized changes or data exposure.
