CVE-2020-36494: XSS
Published Oct 22, 2021
·Updated
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychanneledit.php via the filename, mid, userid, and templet' parameters.
Affected Software
1 affected component
DedeCMS Dedecms=7.5-sp2
Event History
Oct 22, 2021
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of DedeCMS?
The vulnerability ID of DedeCMS is CVE-2020-36494.
2
What is the severity of CVE-2020-36494?
The severity of CVE-2020-36494 is medium.
3
What is the affected software version of DedeCMS?
The affected software version of DedeCMS is 7.5 SP2.
4
What are the parameters that contain cross-site scripting (XSS) vulnerabilities in DedeCMS?
The parameters that contain cross-site scripting (XSS) vulnerabilities in DedeCMS are `filename`, `mid`, `userid`, and `templet`.
5
Where can I find more information about CVE-2020-36494?
You can find more information about CVE-2020-36494 [here](https://www.vulnerability-lab.com/get_content.php?id=2194).