Vulnerability Description
An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| O-Dyn | Collabtive | >= 3.0 |
Related Weaknesses (CWE)
References
- http://www.collabtive.o-dyn.de/blog/Release NotesVendor Advisory
- https://sisl.lab.uic.edu/projects/chess/cross-site-scripting-in-collabtive/ExploitThird Party Advisory
- http://www.collabtive.o-dyn.de/blog/Release NotesVendor Advisory
- https://sisl.lab.uic.edu/projects/chess/cross-site-scripting-in-collabtive/ExploitThird Party Advisory
FAQ
What is CVE-2020-13655?
CVE-2020-13655 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user ha...
How severe is CVE-2020-13655?
CVE-2020-13655 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13655?
Check the references section above for vendor advisories and patch information. Affected products include: O-Dyn Collabtive.