CVE-2021-40541: XSS
Published Oct 11, 2021
·Updated
PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.
Affected Software
1 affected component
PHP-Fusion Phpfusion=9.03.110
Event History
Oct 11, 2021
CVE Published
via MITRE·01:16 PM
Data Sourced
via MITRE·01:16 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-40541.
2
What is the severity of CVE-2021-40541?
The severity of CVE-2021-40541 is medium.
3
Which software version is affected by CVE-2021-40541?
PHPFusion 9.03.110 is affected by CVE-2021-40541.
4
What is the impact of CVE-2021-40541?
CVE-2021-40541 allows an authenticated user to trigger cross-site scripting (XSS) attacks.
5
Is there a fix available for CVE-2021-40541?
There is no known fix available for CVE-2021-40541 at the moment, please refer to the vendor's advisory for updates.