CVE-2023-43232: XSS
A stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-43232?
CVE-2023-43232 is a stored cross-site scripting (XSS) vulnerability in the Website column management function of DedeBIZ v6.2.11.
How does CVE-2023-43232 affect DedeBIZ?
CVE-2023-43232 allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the title parameter of the Website column management function in DedeBIZ v6.2.11.
What is the severity of CVE-2023-43232?
The severity of CVE-2023-43232 is medium, with a severity rating of 5.4.
How can I fix CVE-2023-43232?
To fix CVE-2023-43232, it is recommended to update to a patched version of DedeBIZ or apply the necessary security patches provided by the vendor.
Where can I find more information about CVE-2023-43232?
More information about CVE-2023-43232 can be found at dedebiz.com and in the official documentation and resources provided by the DedeBIZ project.