PT-2021-9636 · Phpgacl · Phpgacl
Claudio Bozzato
·
Published
2021-01-30
·
Updated
2022-06-29
·
CVE-2020-13562
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
phpGACL version 3.3.7
Description
A cross-site scripting issue exists in the template functionality. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this issue in the
action parameter of the phpGACL template.Recommendations
For phpGACL version 3.3.7, consider disabling the template functionality until a patch is available. Restrict access to the template action parameter to minimize the risk of exploitation. Avoid using the
action parameter in the affected template endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpgacl