CVE-2023-31757: XSS
Published May 19, 2023
·Updated
DedeCMS up to v5.7.108 is vulnerable to XSS in sysinfo.php via parameters 'editcfgpowerby' and 'editcfgbeian'
Affected Software
1 affected component
DedeCMS Dedecms=5.7.108
Event History
May 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of DedeCMS XSS vulnerability?
The vulnerability ID of DedeCMS XSS vulnerability is CVE-2023-31757.
2
What is the severity of CVE-2023-31757?
The severity of CVE-2023-31757 is medium with a severity value of 5.4.
3
Which version of DedeCMS is affected by CVE-2023-31757?
DedeCMS version 5.7.108 is affected by CVE-2023-31757.
4
How can an attacker exploit CVE-2023-31757?
An attacker can exploit CVE-2023-31757 by injecting malicious scripts through the 'edit___cfg_powerby' and 'edit___cfg_beian' parameters in sys_info.php.
5
Is there a fix available for CVE-2023-31757?
At the moment, there is no known fix available for CVE-2023-31757. It is recommended to follow any security advisories or updates from the vendor.