CRITICAL

CVE-2023-3578

CVSS v3

9.8

CRITICAL

EPSS Score

78.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233371.

Technical details

Published
7/10/2023

Frequently asked questions

What is CVE-2023-3578?

A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233371.

Is CVE-2023-3578 actively exploited?

Active exploitation of CVE-2023-3578 has not been confirmed. The EPSS score is 78.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-3578?

CVE-2023-3578 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-3578 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.