CVE-2023-40874: XSS
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/voteadd.php via the votename and voteitem1 parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40874?
CVE-2023-40874 refers to multiple cross-site scripting (XSS) vulnerabilities in DedeCMS up to and including version 5.7.110.
What is the severity of CVE-2023-40874?
The severity of CVE-2023-40874 is medium, with a severity value of 5.4.
How does CVE-2023-40874 affect DedeCMS?
CVE-2023-40874 affects DedeCMS up to and including version 5.7.110, exposing it to multiple cross-site scripting (XSS) vulnerabilities.
What is cross-site scripting (XSS)?
Cross-Site Scripting (XSS) is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
How can I fix CVE-2023-40874 in DedeCMS?
To fix CVE-2023-40874 in DedeCMS, it is recommended to update to a version beyond 5.7.110 where the XSS vulnerabilities have been patched.