First published: Thu May 07 2020(Updated: )
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Php-fusion | =9.03.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12706 is a vulnerability that allows remote attackers to inject arbitrary web script or HTML through multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50.
CVE-2020-12706 has a severity rating of 5.4 (medium).
Remote attackers can exploit CVE-2020-12706 by injecting arbitrary web script or HTML through the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php.
To fix CVE-2020-12706, it is recommended to update PHP-Fusion to version 9.03.51 or later.
You can find more information about CVE-2020-12706 on the following references: [GitHub Commit](https://github.com/php-fusion/PHP-Fusion/commit/67273e546642d39451858a47296957807c9abd5f), [GitHub Issue](https://github.com/php-fusion/PHP-Fusion/issues/2306), [ExploitDB](https://www.exploit-db.com/exploits/48404).