First published: Tue Nov 02 2021(Updated: )
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Phpfusion | =9.03.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23754 is a Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.50.
CVE-2020-23754 has a severity rating of critical with a score of 9.6 out of 10.
CVE-2020-23754 allows attackers to execute arbitrary code via the polls feature in PHP-Fusion 9.03.50.
Yes, upgrading PHP-Fusion to a version higher than 9.03.50 will fix CVE-2020-23754.
More information about CVE-2020-23754 can be found on the GitHub issue page and the provided reference links.