References https://nvd.nist.gov/vuln/detail/CVE-2023-30380 https://access.redhat.com/security/cve/cve-2023-30380 https://app.opencve.io/cve/?vendor=dedecms&page=4 https://vulmon.com/searchpage?q=dedecms+dedecms+5.7.107 https://github.com/cisagov/vulnrichment/blob/develop/2023/30xxx/CVE-2023-30380.json https://www.nsfocus.net/vulndb/80504 https://www.dptech.com/uploadfile/2023/0428/20230428042407562.pdf https://pentest-tools.com/vulnerabilities-exploits/dedecms-57107-multiple-vulnerabilities_19280 https://www.thehackerwire.com/vulnerability/CVE-2023-30380/ https://www.thehackerwire.com/vendor/dedecms/?thw_page=5
Related VulnerabilitiesPoCCVE-2024-57241: DedeCMS - Open Redirect via download.phpPoC(CVE-2025-15004)DedeCMS至5.7.118版本freelist_main.php文件orderby参数SQL注入漏洞PoCCVE-2017-17731: DedeCMS 5.7 - SQL InjectionPoCCVE-2018-18608: DedeCMS 5.7 SP2 - Cross-Site ScriptingPoCCVE-2018-6910: DedeCMS 5.7 - Path DisclosurePoCCVE-2018-7700: DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code ExecutionPoCCVE-2023-2059: DedeCMS 5.7.87 - Directory TraversalPoCCVE-2023-3578: DedeCMS 5.7.109 - Server-Side Request ForgeryPoCCVE-2023-49494: DedeCMS v5.7.111 - Cross-Site ScriptingPoCCVE-2018-6910: DedeCMS 5.7 Web Path DisclosurePoCCVE-2018-7700: Dedecms V5.7 后台任意代码执行PoCdedecms-carbuyaction-fileinclude: DedeCmsV5.6 Carbuyaction Fileinclude