First published: Tue Apr 28 2020(Updated: )
An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Php-fusion | =9.03.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-12438.
The severity of CVE-2020-12438 is medium with a CVSS score of 5.4.
The affected software is PHP-Fusion version 9.03.50.
The vulnerability allows for cross-site scripting (XSS) attacks by exploiting the lack of proper XSS security measures in the banners.php page.
The XSS vulnerability in PHP-Fusion 9.03.50 can be exploited by using HTML event handlers to execute malicious JavaScript code.
Yes, a fix for CVE-2020-12438 is available. Please refer to the provided references for more information on how to fix this vulnerability.