CVE-2020-36492: XSS
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component selectmedia.php via the activepath, keyword, tag, fmdo=x&filename, CKEditor and CKEditorFuncNum parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-36492?
CVE-2020-36492 is a vulnerability found in DedeCMS v7.5 SP2 that allows for multiple cross-site scripting (XSS) attacks.
How severe is CVE-2020-36492?
CVE-2020-36492 is considered a medium severity vulnerability with a CVSS score of 5.4.
Which component of DedeCMS v7.5 SP2 is affected by CVE-2020-36492?
The component select_media.php is affected by CVE-2020-36492.
What parameters in DedeCMS v7.5 SP2 are vulnerable to cross-site scripting (XSS) attacks in CVE-2020-36492?
The `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor`, and `CKEditorFuncNum` parameters in DedeCMS v7.5 SP2 are vulnerable to cross-site scripting (XSS) attacks in CVE-2020-36492.
Is there a fix available for CVE-2020-36492?
At the moment, there is no known fix available for CVE-2020-36492. It is recommended to follow any official advisories or patches provided by the vendor for a solution.