CVE-2020-23185: XSS
Published Jul 2, 2021
·Updated
A stored cross site scripting (XSS) vulnerability in /administration/settingsecurity.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
Affected Software
1 affected component
PHP-Fusion php-fusion=9.03.60
Event History
Jul 2, 2021
CVE Published
via MITRE·05:51 PM
Data Sourced
via MITRE·05:51 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-23185.
2
What is the severity rating for CVE-2020-23185?
CVE-2020-23185 has a severity rating of medium, with a CVSS score of 5.4.
3
What software version is affected by CVE-2020-23185?
CVE-2020-23185 affects PHP-Fusion version 9.03.60 exactly.
4
How does CVE-2020-23185 impact security?
CVE-2020-23185 is a stored cross-site scripting (XSS) vulnerability that allows authenticated attackers to execute arbitrary web scripts or HTML.
5
Is there a fix available for CVE-2020-23185?
At the time of writing, there is no official fix available for CVE-2020-23185. It is recommended to follow the vendor's security advisories for any updates or patches.