PT-2024-10839 · Discuzx · Discuzx

CVE-2020-36828

·

Published

2024-03-31

·

Updated

2024-05-17

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions DiscuzX versions up to 3.4-20200818
Description A problematic issue was found in the function show next step of the file upload/install/include/install function.php. The manipulation of the argument uchidden leads to cross-site scripting. It is possible to launch the attack remotely.
Recommendations For DiscuzX versions up to 3.4-20200818, upgrade to version 3.4-20210119 to address this issue. As a temporary workaround, consider restricting access to the show next step function in the install function.php file until the upgrade is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36828

Affected Products

Discuzx