CVE-2020-23044: XSS
Published Oct 22, 2021
·Updated
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component filepicview.php via the activepath, keyword, tag, fmdo=x&filename, CKEditor and CKEditorFuncNum parameters.
Affected Software
1 affected component
DedeCMS Dedecms=7.5-sp2
Event History
Oct 22, 2021
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-23044.
2
What is the severity of CVE-2020-23044?
The severity of CVE-2020-23044 is medium with a score of 5.4.
3
What software is affected by CVE-2020-23044?
DedeCMS version 7.5 SP2 is affected by CVE-2020-23044.
4
What are the parameters that can be exploited in DedeCMS v7.5 SP2?
The parameters that can be exploited in DedeCMS v7.5 SP2 are `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor`, and `CKEditorFuncNum`.
5
Where can I find more information about CVE-2020-23044?
You can find more information about CVE-2020-23044 at the following link: https://www.vulnerability-lab.com/get_content.php?id=2195.