A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS of the file /plus/carbuyaction.php of the component HTTP POST Request Handler. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2024-12183. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.