CVE-2018-6881: Dedecms

Medium severity, CVSS 5.3. EPSS: 2.2% chance of exploitation in the next 30 days.

EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.

Affected products

  • Dedecms Dedecms: version 5.7 only
  • Phome Empirecms: version 6.6 only; version 7.0 only; version 7.2 only

Published 2018-02-12. Last modified 2026-06-17.