CVE-2017-17731 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in DedeCMS affects v. through 5.7.


DedeCMS is an open-source content management system (CMS) developed in China. It is widely used for creating and managing websites, especially in the Chinese-speaking regions. The CMS offers a range of features, including user management, content creation, website customization, and SEO optimization. Its user-friendly interface and flexible architecture make it a preferred choice for many website creators and administrators.

However, this widely used CMS is also prone to vulnerabilities like any other software system. One such vulnerability is the CVE-2017-17731, which was detected in DedeCMS version 5.7. The vulnerability was located in the plus/recommend.php file, which allowed attackers to exploit the $_FILES superglobal through SQL injection commands. This vulnerability enabled unauthorized access to the website's database, putting confidential information and other digital assets at risk.

If this vulnerability is exploited, it can lead to severe consequences for the website owner. Attackers may gain access to personal or sensitive data, compromise the website's functionality, or inject malicious code into the website. This may lead to a complete loss of control over the website and significant damage to the organization's reputation, leading to a loss of customer trust and loyalty.

