CVE-2023-40875: XSS
Published Aug 24, 2023
·Updated
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/voteedit.php via the votename and votenote parameters.
Affected Software
1 affected component
DedeCMS Dedecms<=5.7.110
Event History
Aug 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this DedeCMS vulnerability?
The vulnerability ID for this DedeCMS vulnerability is CVE-2023-40875.
2
What is the severity of CVE-2023-40875?
CVE-2023-40875 has a severity rating of medium (5.4).
3
How does this vulnerability affect DedeCMS?
This vulnerability affects DedeCMS versions up to and including 5.7.110.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
How can I fix the XSS vulnerabilities in DedeCMS?
To fix the XSS vulnerabilities in DedeCMS, it is recommended to update to a version beyond 5.7.110 or apply any patches provided by the vendor.