-
Notifications
You must be signed in to change notification settings - Fork 137
20200722 Reflected XSS In Managedinstalls Module
Arjen van Bochoven edited this page Jul 22, 2020
·
1 revision
Reflected XSS In Managedinstalls Module - CVE-2020-15883
Reflected cross-site scripting (XSS) is a client side vulnerability allowing arbitrary javascript execution based on request parameters reflected in the body of the response. The application fails to escape dangerous characters from the URL while building the page. This could allow client code execution and arbitrary operations in the context of the user when they click a malicious link from the trusted application.
- Version specific upgrade notes - https://github.com/munkireport/munkireport-php/wiki/How-to-Upgrade-Versions
- General upgrade documentation - https://github.com/munkireport/munkireport-php/wiki/General-Upgrade-Procedures
- Update the
managedinstalls
module to v2.6 - Or disable the
managedinstalls
module by removing it from theMODULES=
setting in the server config.
- General Upgrade Procedures
- How to Upgrade Versions
- Troubleshooting Upgrades
- Migrating sqlite to MySQL