CVE-2020-11055
PHP vulnerability analysis and mitigation

Overview

A cross-site scripting (XSS) vulnerability was discovered in BookStack versions greater than or equal to 0.18.0 and less than 0.29.2. The vulnerability was identified and disclosed on May 2, 2020, and was assigned CVE-2020-11055. The vulnerability affected the comment creation functionality in BookStack, a self-hosted platform for organizing and storing information (GitHub Advisory, JVN Advisory).

Technical details

The vulnerability allowed users with comment creation permissions to directly POST HTML content to the system, which would then be stored in comments and executed when viewed by other users. This created a stored XSS condition where malicious JavaScript code could be injected and executed in other users' browsers. The vulnerability was assigned a CVSS v3.1 base score of 5.4 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N (JVN Advisory).

Impact

The vulnerability primarily impacted scenarios where untrusted users were given permission to create comments. When exploited, it allowed attackers to execute arbitrary JavaScript code in the context of other users' browsers who viewed the malicious comments. This could potentially lead to theft of user session data or other malicious actions performed in the context of the victim's browser (GitHub Advisory).

Exploitability

The vulnerability required an attacker to have valid credentials with comment creation permissions in the BookStack system. While this limited the potential attack surface, environments where comment permissions were given to untrusted users were particularly at risk (BookStack Blog).

Mitigation and workarounds

The vulnerability was patched in BookStack version 0.29.2. After upgrading, administrators must run the command 'php artisan bookstack:regenerate-comment-content' to remove any pre-existing dangerous content. As temporary workarounds, administrators can either disable comments entirely in the system settings or restrict comment creation permissions to trusted users only (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-56825HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56829HIGH8.1
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56830MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-56831MEDIUM6.5
  • PHP logoPHP
  • shopper/framework
NoYesSep 11, 2026
CVE-2026-49992MEDIUM6.3
  • PHP logoPHP
  • kimai/kimai
NoYesSep 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management