PT-2021-9638 · Phpgacl · Phpgacl
Published
2020-10-23
·
Updated
2022-07-29
·
CVE-2020-13564
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
phpGACL version 3.3.7
Description
A cross-site scripting issue exists in the template functionality. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this issue in the
acl id parameter.Recommendations
For phpGACL version 3.3.7, consider restricting access to the template functionality until a patch is available. As a temporary workaround, avoid using the
acl id parameter in the affected template endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpgacl