CVE-2023-40876: XSS
Published Aug 24, 2023
·Updated
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelistadd.php via the title parameter.
Affected Software
1 affected component
DedeCMS Dedecms<=5.7.110
Event History
Aug 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-40876?
CVE-2023-40876 is a cross-site scripting (XSS) vulnerability found in DedeCMS up to and including version 5.7.110.
2
What is the severity of CVE-2023-40876?
The severity of CVE-2023-40876 is medium, with a severity value of 5.4.
3
How does CVE-2023-40876 affect DedeCMS?
CVE-2023-40876 affects DedeCMS up to and including version 5.7.110, allowing an attacker to exploit a cross-site scripting vulnerability.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-40876?
The Common Weakness Enumeration (CWE) for CVE-2023-40876 is CWE-79, which is related to cross-site scripting (XSS) vulnerabilities.
5
How can I fix CVE-2023-40876?
To fix CVE-2023-40876, it is recommended to update DedeCMS to a version higher than 5.7.110.