First published: Thu Dec 14 2023(Updated: )
Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms v6 | =6.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31546 is classified as a high severity Cross Site Scripting (XSS) vulnerability.
To fix CVE-2023-31546, you should implement input validation and sanitization on the search feature to prevent malicious code execution.
CVE-2023-31546 affects DedeBIZ version 6.0.3.
CVE-2023-31546 enables attackers to run arbitrary code through a Cross Site Scripting (XSS) attack.
If you are using DedeBIZ v6.0.3, you should promptly update to a patched version and review your input handling methods.