PT-2021-9637 · Phpgacl · Phpgacl

Published

2020-10-23

·

Updated

2022-07-29

·

CVE-2020-13563

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpGACL version 3.3.7
Description A cross-site scripting issue exists in the template functionality. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this issue in the group id parameter.
Recommendations For phpGACL version 3.3.7, consider restricting access to the template functionality until a fix is available. As a temporary workaround, avoid using the group id parameter in the affected template endpoint.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01886
CVE-2020-13563

Affected Products

Phpgacl