URL Redirection Vulnerability in Dedecms by Dedecms Team
CVE-2024-57241

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 February 2025

Summary

The Dedecms web application version 5.71sp1 and earlier is affected by a URL redirection vulnerability due to a logic error that fails to adequately validate input from GET requests. This flaw allows attackers to manipulate URLs, potentially leading users to malicious sites without their knowledge. It is crucial for users of Dedecms to monitor their systems and implement measures to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.