CVE-2023-53928: PHPFusion 9.10.30 Stored Cross-Site Scripting via File Manager Upload
PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload SVG files with script tags that execute arbitrary JavaScript when viewed, potentially stealing user session information or performing client-side attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53928?
CVE-2023-53928 is considered a medium-severity vulnerability due to the potential for data theft through stored cross-site scripting.
How do I fix CVE-2023-53928?
To mitigate CVE-2023-53928, ensure that SVG file uploads are properly validated to prevent malicious scripts from being executed.
What software versions are affected by CVE-2023-53928?
CVE-2023-53928 specifically affects PHPFusion version 9.10.30.
What type of vulnerability is CVE-2023-53928?
CVE-2023-53928 is a stored cross-site scripting vulnerability that allows for the execution of arbitrary JavaScript.
Can attackers exploit CVE-2023-53928 remotely?
Yes, attackers can exploit CVE-2023-53928 remotely by uploading malicious SVG files via the file manager.