CVE-2020-24708: XSS
Published Oct 28, 2020
·Updated
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.
Affected Software
1 affected component
Getgophish Gophish<0.11.0
Remediation
Event History
Oct 28, 2020
CVE Published
via MITRE·07:32 PM
Data Sourced
via MITRE·07:32 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24708?
CVE-2020-24708 has been rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2020-24708?
To fix CVE-2020-24708, upgrade Gophish to version 0.11.0 or later as it contains the necessary patches.
3
What type of vulnerability is CVE-2020-24708?
CVE-2020-24708 is a Cross Site Scripting (XSS) vulnerability affecting Gophish.
4
Which versions of Gophish are affected by CVE-2020-24708?
CVE-2020-24708 affects all versions of Gophish prior to 0.11.0.
5
How does CVE-2020-24708 affect Gophish users?
CVE-2020-24708 allows attackers to inject malicious scripts via the Host field in the send profile form, potentially compromising user data.