CVE-2020-16632: XSS
Published May 14, 2021
·Updated
A XSS Vulnerability in /uploads/dede/actionsearch.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.
Affected Software
1 affected component
DedeCMS Dedecms=5.7-sp2
Event History
May 14, 2021
CVE Published
via MITRE·11:20 PM
Data Sourced
via MITRE·11:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this XSS vulnerability?
The vulnerability ID is CVE-2020-16632.
2
What is the affected software version of this vulnerability?
The affected software version is DedeCMS 5.7 SP2.
3
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by sending a specially crafted keyword parameter to the /uploads/dede/action_search.php page.
4
What is the severity rating of this vulnerability?
The severity rating for this vulnerability is medium with a CVSS score of 5.4.
5
Is there a fix available for this vulnerability?
At the moment, there is no official fix available. It is recommended to apply any available patches or updates provided by the vendor to mitigate the risk.