SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-27533

A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.

MEDIUM 5.4EPSS 3.56%

Does this matter?

Lower severity and a low EPSS score (3.56%). Track it; it rarely justifies an emergency change on its own.

Description

A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
3.56% probability · 89th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
dedecms/dedecms
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.