Vulnerability record · CVE-2020-13563 · published 1 February 2021
CVE-2020-13563: phpGACL template group_id parameter reflected XSS
PPhpgacl Project · Phpgacl
phpGACL 3.3.7 fails to properly sanitize the group_id parameter in its template functionality, allowing a crafted HTTP request to inject arbitrary JavaScript. The flaw also affects OpenEMR, which bundles phpGACL. Because the script executes in the victim's browser session, it can be used to hijack sessions or manipulate application actions.
Description
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template group_id parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityHigh EPSS and a public exploit reference make exploitation likely, though the medium CVSS and required user interaction temper severity.
What it is
phpGACL 3.3.7 fails to properly sanitize the group_id parameter in its template functionality, allowing a crafted HTTP request to inject arbitrary JavaScript. The flaw also affects OpenEMR, which bundles phpGACL. Because the script executes in the victim's browser session, it can be used to hijack sessions or manipulate application actions.
Impact
An attacker can execute arbitrary JavaScript in the context of a victim's browser session, potentially stealing session cookies or performing actions as the victim. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network via a crafted URL containing the malicious group_id parameter; no authentication is required (PR:N), but the victim must be induced to click the link (UI:R).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.75856, 99.5th percentile) and the Talos advisory is tagged as an exploit reference, indicating public proof-of-concept availability.
What to do
- Apply the vendor patch or upgrade phpGACL/OpenEMR to a fixed release if one is available.
- If patching is not immediately possible, restrict network access to the affected phpGACL/OpenEMR interfaces.
- Encode or reject the group_id parameter at the application layer and enforce output encoding for template rendering.
- Deploy a WAF rule to block script payloads in the group_id parameter.
- Review and harden session cookie flags (HttpOnly, Secure, SameSite) to limit XSS impact.
Detection
- Search web server logs for requests containing script tags, event handlers, or encoded JavaScript in the group_id parameter.
- Monitor for anomalous outbound requests or cookie exfiltration patterns from clients that accessed phpGACL/OpenEMR pages.
- Alert on WAF or IDS signatures matching reflected XSS attempts against the template endpoint.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1177 | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1177 | ExploitThird Party Advisory |
Track CVE-2020-13563 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13563), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.