First published: Fri Oct 22 2021(Updated: )
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | =7.5-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-36490.
The severity of CVE-2020-36490 is medium with a CVSS score of 5.4.
The affected software for CVE-2020-36490 is DedeCMS version 7.5 SP2.
The parameters vulnerable to cross-site scripting (XSS) in DedeCMS version 7.5 SP2 are 'activepath', 'keyword', 'tag', 'fmdo=x&filename', 'CKEditor', and 'CKEditorFuncNum'.
At this time, there is no known fix for CVE-2020-36490. It is recommended to update to a newer version of the software when one becomes available.