CVE-2020-13655Cross-site Scripting in Collabtive

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 41.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 31
Latest updateMay 24

Description

An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

1
GHSA
GHSA-866h-7g87-7xj6: An issue was discovered in Collabtive 32022-05-24
CVE-2020-13655 — Cross-site Scripting in Collabtive | cvebase