CVE-2020-36490: XSS
Published Oct 22, 2021
·Updated
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component filemanageview.php via the activepath, keyword, tag, fmdo=x&filename, CKEditor and CKEditorFuncNum parameters.
Affected Software
1 affected component
DedeCMS Dedecms=7.5-sp2
Event History
Oct 22, 2021
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-36490.
2
What is the severity of CVE-2020-36490?
The severity of CVE-2020-36490 is medium with a CVSS score of 5.4.
3
What is the affected software for CVE-2020-36490?
The affected software for CVE-2020-36490 is DedeCMS version 7.5 SP2.
4
What are the parameters that are vulnerable to cross-site scripting (XSS) in DedeCMS version 7.5 SP2?
The parameters vulnerable to cross-site scripting (XSS) in DedeCMS version 7.5 SP2 are 'activepath', 'keyword', 'tag', 'fmdo=x&filename', 'CKEditor', and 'CKEditorFuncNum'.
5
Is there any fix available for CVE-2020-36490?
At this time, there is no known fix for CVE-2020-36490. It is recommended to update to a newer version of the software when one becomes available.