First published: Fri May 19 2023(Updated: )
DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian'
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | =5.7.108 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of DedeCMS XSS vulnerability is CVE-2023-31757.
The severity of CVE-2023-31757 is medium with a severity value of 5.4.
DedeCMS version 5.7.108 is affected by CVE-2023-31757.
An attacker can exploit CVE-2023-31757 by injecting malicious scripts through the 'edit___cfg_powerby' and 'edit___cfg_beian' parameters in sys_info.php.
At the moment, there is no known fix available for CVE-2023-31757. It is recommended to follow any security advisories or updates from the vendor.