VulnerabilityModified
CVE-2020-15883
A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the last two URL parameters (through which installed packages names and versions are…
MEDIUM 6.1EPSS 1.16%
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the last two URL parameters (through which installed packages names and versions are reported).
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- managedinstalls project/managedinstalls
- Source
- cve@mitre.org
References
- https://github.com/munkireport/managedinstalls/releases/tag/v2.6Release Notes, Third Party Advisory
- https://github.com/munkireport/munkireport-phpThird Party Advisory
- https://github.com/munkireport/munkireport-php/releases/tag/v5.6.3Release Notes, Third Party Advisory
- https://github.com/munkireport/munkireport-php/wiki/20200722-Reflected-XSS-In-Managedinstalls-ModuleThird Party Advisory
- https://github.com/munkireport/managedinstalls/releases/tag/v2.6Release Notes, Third Party Advisory
- https://github.com/munkireport/munkireport-phpThird Party Advisory
- https://github.com/munkireport/munkireport-php/releases/tag/v5.6.3Release Notes, Third Party Advisory
- https://github.com/munkireport/munkireport-php/wiki/20200722-Reflected-XSS-In-Managedinstalls-ModuleThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.