CVE-2018-18579: XSS
Published Oct 22, 2018
·Updated
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter.
Affected Software
1 affected component
DedeCMS Dedecms=5.7-sp2
Event History
Oct 22, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18579?
CVE-2018-18579 is considered a medium severity reflected XSS vulnerability.
2
How does CVE-2018-18579 affect DedeCMS?
CVE-2018-18579 affects DedeCMS 5.7 SP2 by allowing attackers to inject malicious scripts via the 'folder' parameter in the /member/pm.php endpoint.
3
How do I fix CVE-2018-18579?
To fix CVE-2018-18579, ensure that user inputs are properly validated and sanitized before being processed by the application.
4
Is CVE-2018-18579 easily exploitable?
Yes, CVE-2018-18579 can be easily exploited by an attacker with knowledge of the application's URL structure.
5
What is the recommended action for users of DedeCMS 5.7 SP2 regarding CVE-2018-18579?
Users of DedeCMS 5.7 SP2 should apply security patches and stay updated with the latest available version to mitigate risks associated with CVE-2018-18579.