First published: Mon Jun 01 2020(Updated: )
modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by placing %00 before the payload.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citrix Receiver | <=20.0.950 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13758 has a medium severity level due to its potential for cross-site scripting (XSS) vulnerabilities.
To fix CVE-2020-13758, upgrade the Bitrix24 software to a version higher than 20.0.950.
CVE-2020-13758 allows attackers to perform cross-site scripting (XSS) attacks using specially crafted URLs.
CVE-2020-13758 affects Bitrix24 versions up to and including 20.0.950.
You can determine your vulnerability to CVE-2020-13758 by checking your Bitrix24 version and comparing it to the affected versions.