CVE-2024-12180: DedeCMS article_add.php cross site scripting
Published Dec 4, 2024
·Updated
A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file /member/articleadd.php. The manipulation of the argument body leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
DedeCMS Dedecms<5.7.116
Event History
Dec 4, 2024
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12180?
CVE-2024-12180 is classified as problematic due to its potential for exploitation via cross-site scripting.
2
How do I fix CVE-2024-12180?
To fix CVE-2024-12180, update DedeCMS to the latest version that addresses this vulnerability.
3
What file is affected by CVE-2024-12180?
The affected file in CVE-2024-12180 is /member/article_add.php.
4
What type of attack can be launched using CVE-2024-12180?
CVE-2024-12180 allows for a remote cross-site scripting (XSS) attack.
5
Which versions of DedeCMS are vulnerable to CVE-2024-12180?
Versions of DedeCMS prior to 5.7.116 are vulnerable to CVE-2024-12180.