Cross Site Scripting vulnerability in DedeCMS v.5.7 allows a local attacker to execute arbitrary code via a crafted payload to the stepselect_main.php component.
No PoCs from references.
- https://github.com/fkie-cad/nvd-json-data-feeds