PleskWin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-11583 - Vulnerability Database

PleskWin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-11583

Medium
Reference: CVE-2020-11583
Title: PleskWin Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript HTML or CSS via a GET parameter.