First published: Thu Aug 24 2023(Updated: )
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the votename and voteitem1 parameters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dedecms Dedecms | <=5.7.110 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40874 refers to multiple cross-site scripting (XSS) vulnerabilities in DedeCMS up to and including version 5.7.110.
The severity of CVE-2023-40874 is medium, with a severity value of 5.4.
CVE-2023-40874 affects DedeCMS up to and including version 5.7.110, exposing it to multiple cross-site scripting (XSS) vulnerabilities.
Cross-Site Scripting (XSS) is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
To fix CVE-2023-40874 in DedeCMS, it is recommended to update to a version beyond 5.7.110 where the XSS vulnerabilities have been patched.