Description
A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Problem types
Timeline
| 2026-06-01: | Advisory disclosed |
| 2026-06-01: | VulDB entry created |
| 2026-06-01: | VulDB entry last update |
Credits
R21Z20 (VulDB User)
VulDB Vulnerability Moderation Team
References
vuldb.com/vuln/367676 (VDB-367676 | DedeCMS download.php base64_decode server-side request forgery)
vuldb.com/vuln/367676/cti (VDB-367676 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/cve/CVE-2026-10581 (CVE-2026-10581 | CVE Analysis and Report)
vuldb.com/submit/829404 (Submit #829404 | DedeCMS DedeCMS Content Management System v5.7.88 Server-Side Request Forgery (SSRF) / Open Redirect)