CVE-2020-23658: XSS
Published Aug 26, 2020
·Updated
PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/memberpollpanel/polladmin.php.
Affected Software
1 affected component
PHP-Fusion php-fusion=9.03.60
Event History
Aug 26, 2020
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
Description
Frequently Asked Questions
1
What is CVE-2020-23658?
CVE-2020-23658 is a Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60.
2
How does CVE-2020-23658 impact PHP-Fusion?
CVE-2020-23658 allows an attacker to execute malicious scripts in the context of a victim's browser, potentially leading to account hijacking or other malicious activities.
3
What versions of PHP-Fusion are affected by CVE-2020-23658?
PHP-Fusion 9.03.60 is the only affected version.
4
What is the severity of CVE-2020-23658?
The severity of CVE-2020-23658 is medium (5.4) according to the CVSS v3.1 scoring system.
5
How can I fix CVE-2020-23658 in PHP-Fusion?
To fix CVE-2020-23658, users should upgrade to a fixed version of PHP-Fusion, if available, or apply any patches provided by the vendor.