CVE-2020-12708: XSS
Published May 7, 2020
·Updated
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the catid parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.
Affected Software
1 affected component
PHP-Fusion php-fusion=9.03.50
Event History
May 7, 2020
CVE Published
via MITRE·07:07 PM
Data Sourced
via MITRE·07:07 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for these cross-site scripting vulnerabilities?
The vulnerability ID for these cross-site scripting vulnerabilities is CVE-2020-12708.
2
What is the severity level of CVE-2020-12708?
The severity level of CVE-2020-12708 is medium (6.1).
3
How can remote attackers exploit CVE-2020-12708?
Remote attackers can exploit CVE-2020-12708 by injecting arbitrary web script or HTML through the cat_id parameter of downloads/downloads.php or article.php.
4
What is the affected software version of CVE-2020-12708?
The affected software version of CVE-2020-12708 is PHP-Fusion 9.03.50.
5
Is there a fix available for CVE-2020-12708?
Yes, a fix is available for CVE-2020-12708. Please refer to the reference link for more information.