CVE-2020-24712: XSS
Published Oct 28, 2020
·Updated
Cross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the IMAP Host field on the account settings page.
Affected Software
1 affected component
Getgophish Gophish<0.11.0
Remediation
Event History
Oct 28, 2020
CVE Published
via MITRE·07:33 PM
Data Sourced
via MITRE·07:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24712?
CVE-2020-24712 is considered a high severity vulnerability due to its potential for Cross Site Scripting (XSS) attacks.
2
How do I fix CVE-2020-24712?
To fix CVE-2020-24712, upgrade Gophish to version 0.11.0 or later.
3
What kind of attack can CVE-2020-24712 facilitate?
CVE-2020-24712 facilitates Cross Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts.
4
In which software version does CVE-2020-24712 exist?
CVE-2020-24712 exists in Gophish versions prior to 0.11.0.
5
What part of Gophish is affected by CVE-2020-24712?
CVE-2020-24712 affects the IMAP Host field on the account settings page of Gophish.