CVE-2025-14648
- EPSS 0.24%
- Veröffentlicht 14.12.2025 07:15:39
- Zuletzt bearbeitet 22.12.2025 18:18:07
A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown functionality of the file /src/admin/catalog_add.php. Such manipulation leads to command injection. It is possible to launch the attack re...
CVE-2025-12927
- EPSS 0.03%
- Veröffentlicht 10.11.2025 02:32:06
- Zuletzt bearbeitet 20.11.2025 20:00:37
A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the file /admin/archives_add.php. Such manipulation of the argument flags[] leads to sql injection. The attack can be executed remotely....
CVE-2025-12861
- EPSS 0.03%
- Veröffentlicht 07.11.2025 16:02:05
- Zuletzt bearbeitet 20.11.2025 20:04:53
A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the file /admin/spec_add.php. This manipulation of the argument flags[] causes sql injection. The attack is possible to be carried ou...
CVE-2025-12860
- EPSS 0.03%
- Veröffentlicht 07.11.2025 15:15:40
- Zuletzt bearbeitet 20.11.2025 20:11:00
A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. The manipulation of the argument orderby results in sql injection. The attack can be executed remotely. The exploit has been made ...
CVE-2025-12859
- EPSS 0.03%
- Veröffentlicht 07.11.2025 15:15:39
- Zuletzt bearbeitet 20.11.2025 20:12:57
A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_edit.php. The manipulation of the argument ids leads to sql injection. Remote exploitation of the attack is possible. The exploit ...
CVE-2024-52771
- EPSS 0.4%
- Veröffentlicht 20.11.2024 17:15:20
- Zuletzt bearbeitet 13.06.2025 14:23:57
DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.
CVE-2024-52770
- EPSS 0.22%
- Veröffentlicht 20.11.2024 17:15:20
- Zuletzt bearbeitet 13.06.2025 14:17:59
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-52769
- EPSS 0.15%
- Veröffentlicht 20.11.2024 17:15:19
- Zuletzt bearbeitet 13.06.2025 14:14:39
An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-44717
- EPSS 0.39%
- Veröffentlicht 29.08.2024 18:15:14
- Zuletzt bearbeitet 13.03.2025 15:15:47
A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-44716
- EPSS 0.39%
- Veröffentlicht 29.08.2024 18:15:14
- Zuletzt bearbeitet 13.03.2025 14:15:31
A cross-site scripting (XSS) vulnerability in DedeBIZ v6.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.