CVE-2020-24709: XSS
Published Oct 28, 2020
·Updated
Cross Site Scripting (XSS) vulnerability in Gophish through 0.10.1 via a crafted landing page or email template.
Affected Software
1 affected component
Getgophish Gophish<=0.10.1
Event History
Oct 28, 2020
CVE Published
via MITRE·07:33 PM
Data Sourced
via MITRE·07:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24709?
CVE-2020-24709 has been classified as a medium-severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2020-24709?
To fix CVE-2020-24709, update Gophish to version 0.10.2 or later.
3
What is affected by CVE-2020-24709?
CVE-2020-24709 affects Gophish versions up to and including 0.10.1.
4
What types of attacks can CVE-2020-24709 enable?
CVE-2020-24709 can enable attackers to execute malicious scripts in the context of a user's browser.
5
Is user interaction required for CVE-2020-24709 exploitation?
Yes, exploitation of CVE-2020-24709 typically requires user interaction via a crafted landing page or email template.