Security Advisory

CVE-2026-10581

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-02 02:30:08
Last updated 2026-06-02 13:15:49
Assigner VulDB
CVSS score not scored
State PUBLISHED

Description

A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used.