First published: Thu May 07 2020(Updated: )
In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Php-fusion | =9.03.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12718 is a stored XSS vulnerability in the Preview Comment feature of PHP-Fusion 9.03.50, which can be exploited by an authenticated attacker.
An authenticated attacker can exploit CVE-2020-12718 by using HTML event handlers like ontoggle to bypass the protection mechanism in the Preview Comment feature.
The severity of CVE-2020-12718 is medium with a CVSS score of 5.4.
To fix the CVE-2020-12718 vulnerability, it is recommended to upgrade PHP-Fusion to version 9.03.51 or later.
You can find more information about CVE-2020-12718 on the official GitHub page for PHP-Fusion.