CVE-2020-36497: XSS
Published Oct 22, 2021
·Updated
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtmlhomepage.php via the filename, mid, userid, and templet' parameters.
Affected Software
1 affected component
DedeCMS Dedecms=7.5-sp2
Event History
Oct 22, 2021
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
Description
Frequently Asked Questions
1
What is CVE-2020-36497?
CVE-2020-36497 refers to multiple cross-site scripting (XSS) vulnerabilities in DedeCMS v7.5 SP2.
2
What is the severity level of CVE-2020-36497?
The severity level of CVE-2020-36497 is medium with a score of 6.1.
3
Which component in DedeCMS v7.5 SP2 is affected by CVE-2020-36497?
The component affected by CVE-2020-36497 in DedeCMS v7.5 SP2 is makehtml_homepage.php.
4
What parameters in makehtml_homepage.php are vulnerable to cross-site scripting (XSS) attacks in CVE-2020-36497?
The parameters filename, mid, userid, and templet in makehtml_homepage.php are vulnerable to cross-site scripting (XSS) attacks in CVE-2020-36497.
5
How can I mitigate the cross-site scripting (XSS) vulnerabilities in DedeCMS v7.5 SP2 (CVE-2020-36497)?
To mitigate the cross-site scripting (XSS) vulnerabilities in DedeCMS v7.5 SP2, it is recommended to apply the latest patches or updates provided by the vendor.