CVE-2020-24707: Critical severity gophish vulnerability
Published Oct 28, 2020
·Updated
Gophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.
Affected Software
1 affected component
Getgophish Gophish<0.11.0
Remediation
Event History
Oct 28, 2020
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24707?
CVE-2020-24707 is considered moderate in severity due to the potential for malicious content in CSV exports.
2
How do I fix CVE-2020-24707?
To fix CVE-2020-24707, upgrade Gophish to version 0.11.0 or later.
3
What impact does CVE-2020-24707 have on users?
CVE-2020-24707 allows attackers to create malicious CSV files which could be exploited when opened by users.
4
Which versions of Gophish are affected by CVE-2020-24707?
Gophish versions prior to 0.11.0 are affected by CVE-2020-24707.
5
Is there a workaround for CVE-2020-24707 if I cannot upgrade?
Currently, there is no documented workaround for CVE-2020-24707; it is recommended to upgrade to avoid risks.