First published: Thu May 07 2020(Updated: )
Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Php-fusion | =9.03.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for these cross-site scripting vulnerabilities is CVE-2020-12708.
The severity level of CVE-2020-12708 is medium (6.1).
Remote attackers can exploit CVE-2020-12708 by injecting arbitrary web script or HTML through the cat_id parameter of downloads/downloads.php or article.php.
The affected software version of CVE-2020-12708 is PHP-Fusion 9.03.50.
Yes, a fix is available for CVE-2020-12708. Please refer to the reference link for more information.