DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdox&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
Publication date: Sat, 23 Oct 2021 01:15:00 +0000