First published: Mon Aug 03 2020(Updated: )
A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plesk | =17.8.11 | |
Linux Kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Plesk Onyx vulnerability is CVE-2020-11584.
The severity of CVE-2020-11584 is medium (6.1).
CVE-2020-11584 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter in Plesk Onyx 17.8.11.
To fix CVE-2020-11584 in Plesk Onyx 17.8.11, you should update to a patched version of Plesk.
You can find more information about CVE-2020-11584 at the following link: https://medium.com/@0x00crash/xss-reflected-in-plesk-onyx-and-obsidian-1173a3eaffb5