DedeCMS v5.7 vulnerable to CSRF via /dede/diy_edit.php
CVE-2024-28675
8.8HIGH
What is CVE-2024-28675?
DedeCMS version 5.7 has been identified with a Cross-Site Request Forgery (CSRF) vulnerability that can be exploited via the endpoint /dede/diy_edit.php. This flaw allows unauthorized commands to be transmitted from a user that the web application trusts, potentially leading to unauthorized actions being performed without the user's consent. It is crucial for administrators and users of DedeCMS to implement security measures to mitigate the risks associated with this vulnerability.
