SQL Injection Vulnerability in DeDeCMS by DeDeCMS
CVE-2026-76783
Key Information:
Badges
What is CVE-2026-76783?
A security vulnerability has been identified in DeDeCMS version 53_1_UTF8, particularly in the advancedsearch.php file. This issue allows attackers to manipulate SQL queries through arguments, enabling unauthorized access to the database. The exploit can be executed remotely, putting systems at risk of data exposure or modification. With the vulnerability disclosed publicly, it is essential for users of DeDeCMS to take immediate protective measures to secure their applications.
Affected Version(s)
DeDeCMS 53_1_UTF8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
