<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:dedecms:dedecms:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adedecmsdedecms/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 20 Sep 2026 12:21:13 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adedecmsdedecms/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Injection Vulnerability in DedeCMS</title><link>https://feed.craftedsignal.io/briefs/2026-09-dedecms-code-injection/</link><pubDate>Sun, 20 Sep 2026 12:21:13 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-dedecms-code-injection/</guid><description>DedeCMS versions up to 5.7.118 contain a code injection vulnerability in the plus/mytag_js.php file that allows unauthenticated remote attackers to execute arbitrary code via the aid argument.</description><content:encoded><![CDATA[<p>DedeCMS versions up to and including 5.7.118 are vulnerable to a remote code injection flaw located in the 'plus/mytag_js.php' file. The vulnerability stems from improper input validation of the 'aid' argument, which allows an unauthenticated attacker to inject and execute arbitrary code on the target server. Because the vulnerability is reachable via standard HTTP GET requests to the identified file, it poses a high risk to installations of the affected content management system. Proof-of-concept exploit code has been publicly disclosed, increasing the likelihood of opportunistic exploitation by threat actors. Organizations hosting DedeCMS should verify their version and restrict access to the 'plus/mytag_js.php' endpoint or apply vendor-provided patches.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in unauthenticated remote code execution (RCE) on the web server hosting DedeCMS. This allows an attacker to gain full control over the application, access sensitive database information, exfiltrate user data, or use the compromised server as a pivot point for further lateral movement within the network.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Prioritize the identification of all internet-facing DedeCMS instances in the environment.</li>
<li>Upgrade all DedeCMS installations to a version beyond 5.7.118 immediately.</li>
<li>Implement web application firewall (WAF) rules to block HTTP requests to '/plus/mytag_js.php' containing suspicious characters (e.g., shell metacharacters or alphanumeric strings designed to trigger code execution) in the 'aid' parameter.</li>
<li>Review web server logs for HTTP requests targeting the 'plus/mytag_js.php' file with unusual values in the query string to identify attempted exploitation.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>