Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

1Erkeu

#43267of 53,632
6.1Total CVSS
Vulnerabilities · 1
PT-2022-23487
6.1
2022-09-01
Dedecms · Dedecms · CVE-2022-36583
**Name of the Vulnerable Software and Affected Versions** DedeCMS version 5.7.97 **Description** The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities are located at the `/dede/co do.php` endpoint via the `dopost`, `rpok`, and `aid` parameters. **Recommendations** For DedeCMS version 5.7.97, consider disabling access to the `/dede/co do.php` endpoint until a patch is available. As a temporary workaround, restrict the use of the `dopost`, `rpok`, and `aid` parameters in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.