CVE-2018-9134: Dedecms

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.

Affected products

Published 2018-03-30. Last modified 2026-06-17.