Sceawere

Vulnerability Detail

CVE-2026-19353UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DedeCMS Installation Wizard File Inclusion

Vulnerability Metadata

Severity
Medium
Score / CVSS
5
Creation Date
3h ago
Vendor
n/a
Product
DedeCMS
Attack Type
File Inclusion
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been disclosed to the public and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.0",
  "pubDate": "2026-08-09T13:16:51.923Z",
  "pubdate": "2026-08-09T13:16:51.923Z",
  "executiveSummary": "A file inclusion vulnerability has been identified in DedeCMS up to version 5.7.118 UTF8SP2, specifically within the Installation Wizard component.\nThe vulnerability resides in the _4_Setup function located in install/index.php, which permits remote attackers to manipulate input parameters and induce file inclusion behavior.\nSuccessful exploitation of this flaw can lead to unauthorized file inclusion, potentially compromising the integrity and confidentiality of the underlying hosting environment.\nThe attack vector is network-exposed, allowing remote execution without prior authentication.\nHowever, the exploitation process is characterized by high complexity and is considered difficult to execute successfully, requiring specific conditions or precise payload construction by an adversary.\nPublic disclosure of the exploit increases the risk of active targeting, necessitating immediate defensive oversight and adherence to secure deployment practices for affected installations.",
  "technicalDetails": "The vulnerability is classified as a file inclusion flaw occurring within the installation routine of DedeCMS.\nThe affected component is the Installation Wizard implemented in the install/index.php script, specifically targeting the internal function _4_Setup.\nThe root cause stems from improper validation, sanitization, or handling of input parameters passed to the vulnerable function during the setup phase.\nBecause the execution context relies on parameters processed by _4_Setup, an unauthenticated remote attacker can supply crafted input designed to traverse directories or reference arbitrary local or remote files.\nThe attack flow begins with the adversary identifying an exposed and vulnerable DedeCMS installation where the installation scripts remain accessible or improperly restricted.\nThe attacker crafts a specialized HTTP request targeting install/index.php, interacting with the _4_Setup function by injecting malicious sequences into the parameters expected by the application.\nDue to insufficient input filtering, the application processes the tainted data, leading to the inclusion of unintended files.\nThe impact of this file inclusion depends heavily on the specific parameters and execution context, potentially allowing the inclusion of sensitive configuration data or execution of arbitrary code depending on system configurations and PHP wrappers.\nThe vulnerability affects DedeCMS versions up to 5.7.118 UTF8SP2.\nPrerequisites for a successful attack include network access to the installation directory and the ability to interact with the HTTP interface hosting the vulnerable script, while taking into account the high complexity and difficult exploitability noted for this flaw."
}
CVE-2026-19353: DedeCMS Installation Wizard File Inclusion (MEDIUM Severity, CVSS: 5.0) - Sceawere