CVE-2020-11584: XSS
Published Aug 3, 2020
·Updated
A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
Affected Software
2 affected components
Plesk Onyx=17.8.11
Linux Linux kernel
Event History
Aug 3, 2020
CVE Published
via MITRE·08:05 PM
Data Sourced
via MITRE·08:05 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Plesk Onyx vulnerability?
The vulnerability ID for this Plesk Onyx vulnerability is CVE-2020-11584.
2
What is the severity of CVE-2020-11584?
The severity of CVE-2020-11584 is medium (6.1).
3
How does CVE-2020-11584 affect Plesk Onyx?
CVE-2020-11584 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter in Plesk Onyx 17.8.11.
4
How can I fix CVE-2020-11584 in Plesk Onyx 17.8.11?
To fix CVE-2020-11584 in Plesk Onyx 17.8.11, you should update to a patched version of Plesk.
5
Where can I find more information about CVE-2020-11584?
You can find more information about CVE-2020-11584 at the following link: https://medium.com/@0x00crash/xss-reflected-in-plesk-onyx-and-obsidian-1173a3eaffb5