CVE-2020-18917 describes a critical remote code execution (RCE) vulnerability in DedeCMS 5.7 SP2, specifically within the plus/search.php component. Attackers can exploit this by manipulating the 'typename' parameter to inject and execute arbitrary PHP code, leading to full compromise of the affected system. With a CVSS score of 8.8 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, resulting in high impacts to confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No) and no public exploit intelligence (Metasploit, Nuclei, ExploitDB) or significant community discussion, the high FAUCET Risk Score of 68/100 indicates its potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.7CPE matchmatch criteria | cpe:2.3:a:dedecms:dedecms:5.7:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.