CVE-2020-15883
Summary
| CVE | CVE-2020-15883 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-23 14:15:00 UTC |
| Updated | 2020-09-01 20:39:00 UTC |
| Description | A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the last two URL parameters (through which installed packages names and versions are reported). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| GitHub - munkireport/munkireport-php: A reporting tool for munki |
MISC |
github.com |
Third Party Advisory |
| Release v2.6 · munkireport/managedinstalls · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| 20200722 Reflected XSS In Managedinstalls Module · munkireport/munkireport-php Wiki · GitHub |
MISC |
github.com |
Third Party Advisory |
| Release Munkireport 5.6.3 · munkireport/munkireport-php · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 995949 PHP (Composer) Security Update for munkireport/managedinstalls (GHSA-79xr-v794-wq35)