Vulnerability record · CVE-2020-13562 · published 1 February 2021
CVE-2020-13562: phpGACL template action parameter reflected XSS
PPhpgacl Project · Phpgacl
phpGACL 3.3.7 contains a cross-site scripting flaw in its template functionality. A crafted HTTP request through the template action parameter causes arbitrary JavaScript execution in the victim's browser. The issue also affects OpenEMR, which bundles phpGACL.
Description
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGACL template action parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityHigh EPSS and a public exploit reference raise likelihood, though the medium CVSS and required user interaction temper severity.
What it is
phpGACL 3.3.7 contains a cross-site scripting flaw in its template functionality. A crafted HTTP request through the template action parameter causes arbitrary JavaScript execution in the victim's browser. The issue also affects OpenEMR, which bundles phpGACL.
Impact
An attacker can execute arbitrary JavaScript in the context of a victim's session, enabling session theft, credential phishing, or actions performed as the victim. The CVSS scope change indicates impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network via a crafted URL targeting the template action parameter; no authentication is required, but the victim must be induced to click the link or load the page (UI:R).
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is very high (0.777, 99.5th percentile) and the Talos advisory is tagged as an exploit reference, indicating public technical detail exists.
What to do
- Upgrade phpGACL to a version past 3.3.7 or apply the vendor fix; update OpenEMR to a release containing the patched phpGACL.
- If patching is delayed, restrict network access to phpGACL/OpenEMR interfaces and place them behind authentication or a VPN.
- Deploy a WAF rule or input filtering that blocks script payloads in the template action parameter.
- Set a strict Content-Security-Policy and ensure session cookies use HttpOnly and Secure flags to limit script impact.
Detection
- Search web and proxy logs for requests to phpGACL template endpoints containing script tags, event handlers, or encoded JavaScript in the action parameter.
- Monitor for anomalous outbound requests or referrers originating from phpGACL/OpenEMR pages that could indicate script exfiltration.
- Alert on repeated 200 responses to template URLs with unusual parameter encoding from a single source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1177 | ExploitTechnical DescriptionThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1177 | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2020-13562 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13562), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.