CVE-2024-46372

MEDIUM

dedecms 5.7.115 - Stored Cross-Site Scripting via Advertisement Code Box

Title source: llm
STIX 2.1

Description

DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.

Scores

CVSS v3 6.1
EPSS 0.0020
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
dedecms/dedecms 5.7.115
Published Sep 18, 2024
Tracked Since Feb 18, 2026