CVE-2023-34842
Critical · CVSS 9.8DedeCMS — Remote Code Execution via crafted POST request (Code Injection)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-94
Description
Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.
Search profile — drives PoC discovery
Symbols /dede/tpl.phptpl.phpPOST requestCWE-94
Keywords CVE-2023-34842DedeCMS RCEDedeCMS tpl.phpDedeCMS 5.7.109 exploitDedeCMS remote code executiondedecms tpl.php poc
Versions: through 5.7.109
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z