PT-2021-9638 · Phpgacl · Phpgacl

Published

2020-10-23

·

Updated

2022-07-29

·

CVE-2020-13564

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions phpGACL version 3.3.7
Description A cross-site scripting issue exists in the template functionality. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this issue in the acl id parameter.
Recommendations For phpGACL version 3.3.7, consider restricting access to the template functionality until a patch is available. As a temporary workaround, avoid using the acl id parameter in the affected template endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01885
CVE-2020-13564

Affected Products

Phpgacl