CVE-2023-31546: XSS
Published Dec 14, 2023
·Updated
Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.
Affected Software
1 affected component
DedeBIZ DedeBIZ=6.0.3
Event History
Dec 14, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-31546?
CVE-2023-31546 is classified as a high severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2023-31546?
To fix CVE-2023-31546, you should implement input validation and sanitization on the search feature to prevent malicious code execution.
3
What software versions are affected by CVE-2023-31546?
CVE-2023-31546 affects DedeBIZ version 6.0.3.
4
What type of attack does CVE-2023-31546 enable?
CVE-2023-31546 enables attackers to run arbitrary code through a Cross Site Scripting (XSS) attack.
5
What should I do if I use DedeBIZ v6.0.3 and am concerned about CVE-2023-31546?
If you are using DedeBIZ v6.0.3, you should promptly update to a patched version and review your input handling methods.