First published: Mon Oct 29 2018(Updated: )
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | =5.7-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18782 has been rated as a medium severity vulnerability due to its potential to allow reflected cross-site scripting attacks.
To mitigate CVE-2018-18782, it is recommended to sanitize user inputs related to the ftype parameter in DedeCMS 5.7 SP2.
CVE-2018-18782 specifically affects DedeCMS version 5.7 SP2.
CVE-2018-18782 is a reflected cross-site scripting (XSS) vulnerability.
CVE-2018-18782 can be exploited through the /member/myfriend.php endpoint using the ftype parameter.