Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2020-27533

Description

A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.

POC

Reference

- http://packetstormsecurity.com/files/159772/DedeCMS-5.8-Cross-Site-Scripting.html

Github

- https://github.com/EdgeSecurityTeam/Vulnerability

- https://github.com/tzwlhack/Vulnerability