CVE-2020-36828: DiscuzX install_function.php show_next_step cross site scripting
A vulnerability was found in DiscuzX up to 3.4-20200818. It has been classified as problematic. Affected is the function shownextstep of the file upload/install/include/installfunction.php. The manipulation of the argument uchidden leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.4-20210119 is able to address this issue. The name of the patch is 4a9673624f46f7609486778ded9653733020c567. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-258612.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36828?
CVE-2020-36828 has been classified as a problematic vulnerability.
How do I fix CVE-2020-36828?
To fix CVE-2020-36828, update DiscuzX to a version beyond 3.4-20200818.
What type of vulnerability is CVE-2020-36828?
CVE-2020-36828 is a cross-site scripting (XSS) vulnerability.
What specific function is affected by CVE-2020-36828?
The vulnerability in CVE-2020-36828 affects the function show_next_step in install_function.php.
What can attackers exploit in CVE-2020-36828?
Attackers can exploit CVE-2020-36828 by manipulating the argument uchidden to perform cross-site scripting attacks.