References https://nvd.nist.gov/vuln/detail/CVE-2022-36216 https://avd.aquasec.com/nvd/2022/cve-2022-36216/ https://github.com/advisories/GHSA-whv6-j2g7-vcq4 https://advisories.checkpoint.com/defense/advisories/public/2022/cpai-2022-0808.html/ https://cn-sec.com/archives/tag/cve-2022-36216 https://cve.imfht.com/detail/CVE-2022-36216 https://avd.aliyun.com/product?prod=dedecms&page=4
Related VulnerabilitiesPoCCVE-2024-57241: DedeCMS - Open Redirect via download.phpPoC(CVE-2025-15004)DedeCMS至5.7.118版本freelist_main.php文件orderby参数SQL注入漏洞PoCCVE-2017-17731: DedeCMS 5.7 - SQL InjectionPoCCVE-2018-18608: DedeCMS 5.7 SP2 - Cross-Site ScriptingPoCCVE-2018-6910: DedeCMS 5.7 - Path DisclosurePoCCVE-2018-7700: DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code ExecutionPoCCVE-2023-2059: DedeCMS 5.7.87 - Directory TraversalPoCCVE-2023-3578: DedeCMS 5.7.109 - Server-Side Request ForgeryPoCCVE-2023-49494: DedeCMS v5.7.111 - Cross-Site ScriptingPoCCVE-2018-6910: DedeCMS 5.7 Web Path DisclosurePoCCVE-2018-7700: Dedecms V5.7 后台任意代码执行PoCdedecms-carbuyaction-fileinclude: DedeCmsV5.6 Carbuyaction Fileinclude