CVE-2020-36491: XSS
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tagsmain.php via the activepath, keyword, tag, fmdo=x&filename, CKEditor and CKEditorFuncNum parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-36491?
CVE-2020-36491 is a vulnerability in DedeCMS v7.5 SP2 that allows for multiple cross-site scripting (XSS) attacks.
How severe is the CVE-2020-36491 vulnerability?
The severity of CVE-2020-36491 is medium, with a severity value of 5.4.
What is the affected software?
The affected software is DedeCMS v7.5 SP2.
What is cross-site scripting (XSS)?
Cross-site scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by users.
How can I fix the CVE-2020-36491 vulnerability?
To fix the CVE-2020-36491 vulnerability, it is recommended to update to a patched version of DedeCMS where the cross-site scripting (XSS) vulnerabilities have been fixed.