CyberRota Analysis
AI-GeneratedDede CMS version 5.7.118 is vulnerable to an SQL injection attack through the sqlquery parameter in the sys_sql_query.php component, enabling remote attackers to extract sensitive information from the database. Organizations using this CMS should prioritize patching this vulnerability to mitigate the risk of data breaches. Immediate action is recommended for any entities relying on this version of Dede CMS to safeguard their data integrity and security.
CVE
CVE-2026-51077
Severity
HIGH
CVSS
7.5
EPSS
0.31%
Original NVD Description
SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component