CVE-2020-11583: XSS
Published Aug 3, 2020
·Updated
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
Affected Software
2 affected components
Plesk Obsidian=18.0.17
Microsoft Windows
Event History
Aug 3, 2020
CVE Published
via MITRE·08:12 PM
Data Sourced
via MITRE·08:12 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-11583.
2
What is the severity of CVE-2020-11583?
The severity of CVE-2020-11583 is medium (CVSS score: 6.1).
3
How does the vulnerability in Plesk Obsidian 18.0.17 affect the system?
The vulnerability allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
4
Which software versions are affected by CVE-2020-11583?
Plesk Obsidian 18.0.17 is affected by CVE-2020-11583.
5
Is Plesk Obsidian the only affected software?
Yes, Plesk Obsidian 18.0.17 is the only affected software version.