CVE-2020-10192: Munkireport Project Munkireport
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in Munkireport before 5.3.0.3923. An unauthenticated actor can send a custom XSS payload through the /report/broken_client endpoint. The payload will be executed by any authenticated users browsing the application. This concerns app/views/listings/default.php.
Affected products
- Munkireport Project Munkireport: before 5.3.0 (fixed in 5.3.0)
Published 2020-03-09. Last modified 2026-06-17.