CVE-2021-28280: XSS
Published Apr 29, 2021
·Updated
CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML
Affected Software
1 affected component
PHP-Fusion Phpfusion=9.03.110
Remediation
Event History
Apr 29, 2021
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this CSRF and Cross-site scripting (XSS) vulnerability in PHPFusion?
The vulnerability ID is CVE-2021-28280.
2
What is the affected version of PHPFusion?
The affected version of PHPFusion is 9.03.110.
3
What is the severity rating of CVE-2021-28280?
The severity rating of CVE-2021-28280 is medium (6.1).
4
How can remote attackers exploit this vulnerability?
Remote attackers can exploit this vulnerability by injecting arbitrary web script or HTML.
5
How can I fix this CSRF and Cross-site scripting (XSS) vulnerability in PHPFusion?
To fix this vulnerability, update PHPFusion to a version that includes the necessary fixes or patches provided by the PHPFusion developers.