CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-34842

Critical · CVSS 9.8

DedeCMS — Remote Code Execution via crafted POST request (Code Injection)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-94

Description

Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.

Search profile — drives PoC discovery

Symbols /dede/tpl.phptpl.phpPOST requestCWE-94
Keywords CVE-2023-34842DedeCMS RCEDedeCMS tpl.phpDedeCMS 5.7.109 exploitDedeCMS remote code executiondedecms tpl.php poc
Versions: through 5.7.109

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z