Vulnerability Details CVE-2020-13562
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGACL template action parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.194
EPSS Ranking 95.1%
CVSS Severity
CVSS v3 Score 9.6
CVSS v2 Score 4.3
Products affected by CVE-2020-13562
-
cpe:2.3:a:open-emr:openemr:5.0.2
-
cpe:2.3:a:phpgacl_project:phpgacl:3.3.7