CVE-2020-15041: XSS
Published Jun 24, 2020
·Updated
PHP-Fusion 9.03.60 allows XSS via the administration/sitelinks.php Add Site Link field.
Affected Software
1 affected component
PHP-Fusion php-fusion=9.03.60
Event History
Jun 24, 2020
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-15041.
2
What is the severity level of CVE-2020-15041?
CVE-2020-15041 has a severity level of medium with a CVSS score of 4.8.
3
How can an attacker exploit this vulnerability?
An attacker can exploit CVE-2020-15041 by injecting malicious code through the Add Site Link field in administration/site_links.php.
4
What software versions are affected by CVE-2020-15041?
PHP-Fusion version 9.03.60 is affected by CVE-2020-15041.
5
Where can I find more information about CVE-2020-15041?
You can find more information about CVE-2020-15041 at the following link: [https://github.com/php-fusion/PHP-Fusion/issues/2330](https://github.com/php-fusion/PHP-Fusion/issues/2330).