DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the activepath, keyword, tag, fmdo=x&filename, CKEditor and CKEditorFuncNum parameters.
| Software | From | Fixed in |
|---|---|---|
| dedecms / dedecms | 7.5-sp2 | 7.5-sp2.x |