CVE-2020-23179: XSS
A stored cross site scripting (XSS) vulnerability in administration/settingsmain.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-23179?
CVE-2020-23179 is a stored cross-site scripting (XSS) vulnerability in PHP-Fusion 9.03.50.
How does the vulnerability in PHP-Fusion 9.03.50 work?
The vulnerability allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field.
What is the severity of CVE-2020-23179?
The severity of CVE-2020-23179 is medium with a CVSS score of 5.4.
How can I fix CVE-2020-23179 in PHP-Fusion 9.03.50?
To fix the vulnerability, update PHP-Fusion to a version that is not affected.
Where can I find more information about CVE-2020-23179?
You can find more information about CVE-2020-23179 at the following reference: [GitHub](https://github.com/PHPFusion/PHPFusion/issues/2320).