5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in DedeCMS up to 5.7.118. This impacts an unknown function of the file /freelist_main.php. The manipulation of the argument orderby leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Basic Information
ID
CVE-2025-15004
Source
VulDB
Published
Dec 22, 2025 at 00:02
Affected Product
Vendor
n/a
Product
DedeCMS
Version
5.7.118
Affected Versions
n/a DedeCMS 5.7.118