First published: Fri Sep 21 2018(Updated: )
DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 | =5.7-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16786 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2018-16786, update DedeCMS to a version that is not affected by this vulnerability.
CVE-2018-16786 specifically affects DedeCMS version 5.7 SP2.
CVE-2018-16786 is a cross-site scripting (XSS) vulnerability that can be exploited through the msg parameter.
CVE-2018-16786 can be exploited in the feedback functionality of DedeCMS, specifically through the /plus/feedback_ajax.php endpoint.