VulnerabilityModified
CVE-2020-27533
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
MEDIUM 5.4EPSS 3.56%
Does this matter?
Lower severity and a low EPSS score (3.56%). Track it; it rarely justifies an emergency change on its own.
Description
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 3.56% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- dedecms/dedecms
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/159772/DedeCMS-5.8-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/dedetech/issues/issues/16Exploit, Issue Tracking, Third Party Advisory
- http://packetstormsecurity.com/files/159772/DedeCMS-5.8-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/dedetech/issues/issues/16Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.