Vulnerability Description
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Plesk | Obsidian | 18.0.17 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://medium.com/%400x00crash/xss-reflected-in-plesk-onyx-and-obsidian-1173a3e
- https://medium.com/%400x00crash/xss-reflected-in-plesk-onyx-and-obsidian-1173a3e
FAQ
What is CVE-2020-11583?
CVE-2020-11583 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
How severe is CVE-2020-11583?
CVE-2020-11583 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11583?
Check the references section above for vendor advisories and patch information. Affected products include: Plesk Obsidian, Microsoft Windows.