CVE-2020-13486: Medium severity verbb knock knock vulnerability
Published May 25, 2020
·Updated
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
Affected Software
2 affected componentsFixes available
verbb Knock Knock Craft Cms<1.2.8
composer/verbb/knock-knock<1.2.8
1.2.8
Event History
May 25, 2020
CVE Published
via MITRE·10:38 PM
Data Sourced
via MITRE·10:38 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:18 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-13486?
CVE-2020-13486 is classified as a moderate severity vulnerability due to its potential for malicious redirection.
2
How do I fix CVE-2020-13486?
To fix CVE-2020-13486, update the Knock Knock plugin to version 1.2.8 or later.
3
What systems are affected by CVE-2020-13486?
CVE-2020-13486 affects the Knock Knock plugin versions prior to 1.2.8 used in Craft CMS.
4
What types of attacks can CVE-2020-13486 facilitate?
CVE-2020-13486 can facilitate malicious redirection attacks, potentially leading users to harmful sites.
5
Is there a workaround for CVE-2020-13486?
There are no documented workarounds for CVE-2020-13486, so updating to the latest version is essential.