CVE-2018-18781: XSS
Published Oct 29, 2018
·Updated
DedeCMS 5.7 SP2 allows XSS via the /member/uploadsselect.php f or keyword parameter.
Affected Software
1 affected component
DedeCMS Dedecms=5.7-sp2
Event History
Oct 29, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18781?
CVE-2018-18781 has a medium severity level due to the potential for cross-site scripting exploits.
2
How do I fix CVE-2018-18781?
To fix CVE-2018-18781, update DedeCMS to a version beyond 5.7 SP2 where the vulnerability has been patched.
3
What type of vulnerability is CVE-2018-18781?
CVE-2018-18781 is a cross-site scripting (XSS) vulnerability found in DedeCMS.
4
Where is CVE-2018-18781 located in the DedeCMS code?
CVE-2018-18781 is located in the /member/uploads_select.php file, specifically in the handling of the 'keyword' parameter.
5
Who is affected by CVE-2018-18781?
Users of DedeCMS version 5.7 SP2 are affected by CVE-2018-18781 and should take necessary precautions.