CVE-2024-12183: DedeCMS HTTP POST Request carbuyaction.php RemoveXSS cross site scripting
Published Dec 4, 2024
·Updated
A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS of the file /plus/carbuyaction.php of the component HTTP POST Request Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
DedeCMS Dedecms<5.7.116
Event History
Dec 4, 2024
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12183?
CVE-2024-12183 is classified as a problematic vulnerability.
2
How do I fix CVE-2024-12183?
To fix CVE-2024-12183, update DedeCMS to a version newer than 5.7.116.
3
What type of vulnerability is CVE-2024-12183?
CVE-2024-12183 is a Cross Site Scripting (XSS) vulnerability.
4
Which component is affected by CVE-2024-12183?
CVE-2024-12183 affects the HTTP POST Request Handler in DedeCMS.
5
In which file is CVE-2024-12183 located?
CVE-2024-12183 is located in the file /plus/carbuyaction.php.