CVE-2020-27533

MEDIUM

DedeCMS 5.8 - Cross-Site Scripting in Search Feature

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-27533. PoCs published by Noth.

AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in DedeCMS v5.8 by injecting a malicious script via the 'keyword' parameter in a POST request to the search feature. The PoC shows how an attacker can execute arbitrary JavaScript in the context of a victim's browser.

Description

A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.

Exploits (1)

exploitdb WORKING POC
by Noth · textwebappsphp
https://www.exploit-db.com/exploits/48974

This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in DedeCMS v5.8 by injecting a malicious script via the 'keyword' parameter in a POST request to the search feature. The PoC shows how an attacker can execute arbitrary JavaScript in the context of a victim's browser.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: DedeCMS v5.8
No auth needed
Prerequisites: Access to the target application's search feature
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/dedetech/issues/issues/16
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/159772/DedeCMS-5.8-Cross-Site-Scripting.html

Scores

CVSS v3 5.4
EPSS 0.0346
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
dedecms/dedecms 5.8
Published Oct 22, 2020
Tracked Since Feb 18, 2026