DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.
https://github.com/Limingqian123/cms/blob/main/1.md
https://gist.github.com/Limingqian123/e90a1b86c02bd83d4ab07c08cad9a629