Phpgacl Project maintains a narrowly scoped access-control library that, despite limited product breadth, is embedded in healthcare and enterprise systems where authentication and authorization decisions are critical. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through application-layer input-handling weaknesses including cross-site scripting, SQL injection, and open redirect flaws that arise from the library's web-facing authorization interface. Defenders should assess whether downstream products bundle this library and prioritize remediation where the library handles untrusted user input or session data; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpgacl Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13562MEDIUM A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker | Feb 1, 2021 | 6.1 | 56 | NO | NO |
CVE-2020-13564MEDIUM A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker | Feb 1, 2021 | 6.1 | 55 | NO | NO |
CVE-2020-13563MEDIUM A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker | Feb 1, 2021 | 6.1 | 55 | NO | NO |
CVE-2020-13568HIGH SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerabilit | Apr 13, 2021 | 8.8 | 36 | NO | NO |
CVE-2020-13567CRITICAL Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vu | Apr 18, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-13566HIGH SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerabili | Apr 13, 2021 | 8.8 | 22 | NO | NO |
CVE-2020-13565MEDIUM An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.0.0 (commit babec93f600ff1394f9 | Feb 10, 2021 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpgacl Project.
Media articles that mention a CVE ID that affects a product developed by Phpgacl Project — matched by CVE ID, not by vendor name.