CVE-2018-16786: XSS
Published Sep 21, 2018
·Updated
DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedbackajax.php.
Affected Software
1 affected component
DedeCMS Dedecms=5.7-sp2
Event History
Sep 21, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16786?
CVE-2018-16786 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-16786?
To fix CVE-2018-16786, update DedeCMS to a version that is not affected by this vulnerability.
3
Which versions of DedeCMS are affected by CVE-2018-16786?
CVE-2018-16786 specifically affects DedeCMS version 5.7 SP2.
4
What type of vulnerability is CVE-2018-16786?
CVE-2018-16786 is a cross-site scripting (XSS) vulnerability that can be exploited through the msg parameter.
5
Where can CVE-2018-16786 be exploited?
CVE-2018-16786 can be exploited in the feedback functionality of DedeCMS, specifically through the /plus/feedback_ajax.php endpoint.