A vulnerability was found in Dede CMS 5.7.118. It has been rated as critical. The affected element is an unknown function of the file sys_sql_query.php. This manipulation of the argument sqlquery causes sql injection.
The identification of this vulnerability is CVE-2026-51077. It is possible to initiate the attack remotely. There is no exploit available.