CVE-2023-49492: XSS
Published Dec 7, 2023
·Updated
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php.
Affected Software
1 affected component
DedeCMS Dedecms=5.7.111
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-49492?
CVE-2023-49492 is considered a moderate severity vulnerability due to its reflective cross-site scripting nature.
2
How do I fix CVE-2023-49492?
To fix CVE-2023-49492, update DedeCMS to the latest version or implement input validation on the imgstick parameter at selectimages.php.
3
What type of attack does CVE-2023-49492 enable?
CVE-2023-49492 enables reflective cross-site scripting attacks, which can lead to the execution of malicious scripts in the user's browser.
4
What software versions are affected by CVE-2023-49492?
CVE-2023-49492 specifically affects DedeCMS version 5.7.111.
5
Is user data at risk due to CVE-2023-49492?
Yes, user data may be at risk due to potential exposure to malicious scripts via the reflective XSS vulnerability in CVE-2023-49492.