Back

MEDIUM

DedeCMS makehtml_js_action.php cross-site request forgery

Published Apr 2, 2024

Description

A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/makehtml_js_action.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-258920. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulDB
Published Apr 2, 2024
Updated Aug 1, 2024
Reserved Apr 1, 2024

CISA Vulnrichment

Updated Apr 2, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulDB
Published Apr 2, 2024
Updated Aug 1, 2024

GitHub

No data