CVE-2020-27533
MEDIUMDedeCMS 5.8 - Cross-Site Scripting in Search Feature
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-27533. PoCs published by Noth.
AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in DedeCMS v5.8 by injecting a malicious script via the 'keyword' parameter in a POST request to the search feature. The PoC shows how an attacker can execute arbitrary JavaScript in the context of a victim's browser.
Description
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
Exploits (1)
This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in DedeCMS v5.8 by injecting a malicious script via the 'keyword' parameter in a POST request to the search feature. The PoC shows how an attacker can execute arbitrary JavaScript in the context of a victim's browser.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N