← Vulnerability feed

Vulnerability record · CVE-2020-13563 · published 1 February 2021

CVE-2020-13563: phpGACL template group_id parameter reflected XSS

PPhpgacl Project · Phpgacl

phpGACL 3.3.7 fails to properly sanitize the group_id parameter in its template functionality, allowing a crafted HTTP request to inject arbitrary JavaScript. The flaw also affects OpenEMR, which bundles phpGACL. Because the script executes in the victim's browser session, it can be used to hijack sessions or manipulate application actions.

6.1 CVSS 3.1 Medium EPSS 76% · top 0.5% CWE-80 · CWE-80CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGACL template group_id parameter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityHigh EPSS and a public exploit reference make exploitation likely, though the medium CVSS and required user interaction temper severity.

What it is

phpGACL 3.3.7 fails to properly sanitize the group_id parameter in its template functionality, allowing a crafted HTTP request to inject arbitrary JavaScript. The flaw also affects OpenEMR, which bundles phpGACL. Because the script executes in the victim's browser session, it can be used to hijack sessions or manipulate application actions.

Impact

An attacker can execute arbitrary JavaScript in the context of a victim's browser session, potentially stealing session cookies or performing actions as the victim. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network via a crafted URL containing the malicious group_id parameter; no authentication is required (PR:N), but the victim must be induced to click the link (UI:R).

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.75856, 99.5th percentile) and the Talos advisory is tagged as an exploit reference, indicating public proof-of-concept availability.

What to do

  • Apply the vendor patch or upgrade phpGACL/OpenEMR to a fixed release if one is available.
  • If patching is not immediately possible, restrict network access to the affected phpGACL/OpenEMR interfaces.
  • Encode or reject the group_id parameter at the application layer and enforce output encoding for template rendering.
  • Deploy a WAF rule to block script payloads in the group_id parameter.
  • Review and harden session cookie flags (HttpOnly, Secure, SameSite) to limit XSS impact.

Detection

  • Search web server logs for requests containing script tags, event handlers, or encoded JavaScript in the group_id parameter.
  • Monitor for anomalous outbound requests or cookie exfiltration patterns from clients that accessed phpGACL/OpenEMR pages.
  • Alert on WAF or IDS signatures matching reflected XSS attempts against the template endpoint.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13563 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-24898Open-emr openemr improper authentication vulnerabilityOpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token dis…EPSS 0.56%9.8CVE-2024-22611Open-emr openemr sql injection vulnerabilityOpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controll…EPSS 6.3%9.8CVE-2024-37734Open-emr openemr vulnerabilityAn issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.EPSS 0.80%9.8CVE-2020-13567Open-emr openemr sql injection vulnerabilityMultiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an …EPSS 2.3%9.8CVE-2019-17197Open-emr openemr sql injection vulnerabilityOpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that affects library/patient.inc.EPSS 1.5%9.8CVE-2019-14529Open-emr openemr sql injection vulnerabilityOpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.EPSS 28%9.8CVE-2018-17179Open-emr openemr sql injection vulnerabilityAn issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_fun…EPSS 13%9.8CVE-2018-17181Open-emr openemr sql injection vulnerabilityAn issue was discovered in OpenEMR before 5.0.1 Patch 7. SQL Injection exists in the SaveAudit function in /portal/lib/paylib.php and the portalAudit…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2020-13563), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.