CVE-2020-12706: XSS
Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faqadmin.php or shoutboxpanel/shoutboxadmin.php
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-12706?
CVE-2020-12706 is a vulnerability that allows remote attackers to inject arbitrary web script or HTML through multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50.
How severe is CVE-2020-12706?
CVE-2020-12706 has a severity rating of 5.4 (medium).
How can remote attackers exploit CVE-2020-12706?
Remote attackers can exploit CVE-2020-12706 by injecting arbitrary web script or HTML through the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php.
How can I fix CVE-2020-12706?
To fix CVE-2020-12706, it is recommended to update PHP-Fusion to version 9.03.51 or later.
Where can I find more information about CVE-2020-12706?
You can find more information about CVE-2020-12706 on the following references: [GitHub Commit](https://github.com/php-fusion/PHP-Fusion/commit/67273e546642d39451858a47296957807c9abd5f), [GitHub Issue](https://github.com/php-fusion/PHP-Fusion/issues/2306), [ExploitDB](https://www.exploit-db.com/exploits/48404).