First published: Wed Aug 12 2020(Updated: )
PHP-Fusion 9.03 allows XSS on the preview page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Php-fusion | >=9.0<=9.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17450 is a vulnerability that allows Cross-Site Scripting (XSS) attacks on the preview page of PHP-Fusion 9.03.
CVE-2020-17450 has a severity rating of 6.1, which is considered medium.
CVE-2020-17450 affects PHP-Fusion 9.03, allowing XSS attacks on the preview page.
To fix CVE-2020-17450, it is recommended to upgrade PHP-Fusion to a version that is not affected by the vulnerability.
Yes, you can find more information about CVE-2020-17450 in the reference provided: https://sec-consult.com/en/blog/advisories/multiple-cross-site-scripting-xss-vulnerabilities-in-php-fusion-cms/