Description
An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-5896 | An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:25:16.346Z
Reserved: 2020-05-28T00:00:00.000Z
Link: CVE-2020-13655
No data.
Status : Modified
Published: 2020-08-31T15:15:10.807
Modified: 2024-11-21T05:01:41.557
Link: CVE-2020-13655
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD