First published: Mon Feb 01 2021(Updated: )
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template acl_id parameter.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Phpgacl Project Phpgacl | =3.3.7 | |
Open-emr Openemr | =5.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13564 is a cross-site scripting vulnerability in the template functionality of phpGACL 3.3.7 and Open-emr 5.0.2.
CVE-2020-13564 has a severity score of 6.1 (critical).
CVE-2020-13564 can be exploited by a specially crafted HTTP request that leads to arbitrary JavaScript execution.
phpGACL 3.3.7 and Open-emr 5.0.2 are affected by CVE-2020-13564.
At the time of this report, no official fix has been released for CVE-2020-13564.