CVE

CVE-2018-16786

CVE-2018-16786

DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.

Source: CVE-2018-16786

Exit mobile version