CVE-2020-23754: XSS
Published Nov 2, 2021
·Updated
Cross Site Scripting (XSS) vulnerability in infusions/memberpollpanel/polladmin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.
Affected Software
1 affected component
PHP-Fusion Phpfusion=9.03.50
Event History
Nov 2, 2021
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
Description
Frequently Asked Questions
1
What is CVE-2020-23754?
CVE-2020-23754 is a Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.50.
2
What is the severity of CVE-2020-23754?
CVE-2020-23754 has a severity rating of critical with a score of 9.6 out of 10.
3
How does CVE-2020-23754 impact PHP-Fusion?
CVE-2020-23754 allows attackers to execute arbitrary code via the polls feature in PHP-Fusion 9.03.50.
4
Is there a fix for CVE-2020-23754?
Yes, upgrading PHP-Fusion to a version higher than 9.03.50 will fix CVE-2020-23754.
5
Where can I find more information about CVE-2020-23754?
More information about CVE-2020-23754 can be found on the GitHub issue page and the provided reference links.