PT-2026-6591 · Unknown · Php-Fusion
Unkn0Wn
·
Publicado
2026-02-05
·
Atualizado
2026-02-05
·
CVE-2020-37152
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHP-Fusion version 9.03.50
Description
The application does not properly sanitize user input before rendering it in a browser, which allows attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the
panel content POST parameter in the ''panels.php'' file, resulting in the execution of malicious scripts within the context of the affected site.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Php-Fusion