CVE-2018-18578: XSS
Published Oct 22, 2018
·Updated
DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter.
Affected Software
1 affected component
DedeCMS Dedecms=5.7-sp2
Event History
Oct 22, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18578?
The severity of CVE-2018-18578 is considered medium due to its potential for reflected cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-18578?
To fix CVE-2018-18578, ensure that proper input validation and sanitization measures are implemented on the plus/qrcode.php type parameter.
3
Who is affected by CVE-2018-18578?
CVE-2018-18578 affects users of DedeCMS version 5.7 SP2.
4
What type of vulnerability is CVE-2018-18578?
CVE-2018-18578 is a reflected cross-site scripting (XSS) vulnerability.
5
Can CVE-2018-18578 lead to data theft?
Yes, if exploited, CVE-2018-18578 can lead to data theft and compromise of user sessions.