CVE-2020-27533
MEDIUMCVSS 5.4/10EPSS 3.46%
Last modified
CVE-2020-27533 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.. EPSS estimates a 3.46% chance of exploitation in the next 30 days.
Description
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dedecms | Dedecms | 5.8 |
References
- http://packetstormsecurity.com/files/159772/DedeCMS-5.8-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/dedetech/issues/issues/16Exploit, Issue Tracking, Third Party Advisory
- http://packetstormsecurity.com/files/159772/DedeCMS-5.8-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/dedetech/issues/issues/16Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-27533?
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
How severe is CVE-2020-27533?
CVE-2020-27533 has a CVSS score of 5.4/10 (MEDIUM severity). The EPSS model estimates a 3.46% probability of exploitation in the next 30 days.
How do I fix CVE-2020-27533?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-27518All versions of Windscribe VPN for Mac and Windows <= v2.02.…7.8
- CVE-2020-27519Pritunl Client v1.2.2550.20 contains a local privilege escal…7.8
- CVE-2020-2752Vulnerability in the MySQL Client product of Oracle MySQL (c…5.3
- CVE-2020-27523Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format…7.5
- CVE-2020-27524On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7…7.1
- CVE-2020-2753Vulnerability in the Oracle Workflow product of Oracle E-Bus…5.3
- CVE-2020-27534util/binfmt_misc/check.go in Builder in Docker Engine before…5.3
- CVE-2020-27539Heap overflow with full parsing of HTTP respose in Rosteleco…9.8
- CVE-2020-2754Vulnerability in the Java SE, Java SE Embedded product of Or…3.7
- CVE-2020-27540Bash injection vulnerability and bypass of signature verific…9.8
- CVE-2020-27541Denial of Service vulnerability in Rostelecom CS-C2SHW 5.0.0…7.5
- CVE-2020-27542Rostelecom CS-C2SHW 5.0.082.1 is affected by: Bash command i…6.8
Are you affected by CVE-2020-27533?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
