CVE-2018-9134: Dedecms
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.
Affected products
- Dedecms Dedecms: version 5.7 only
Published 2018-03-30. Last modified 2026-06-17.