PT-2020-13112 · Php Fusion · Php-Fusion

Published

2020-04-28

·

Updated

2020-05-05

·

CVE-2020-12438

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHP-Fusion version 9.03.50
Description A security issue exists in the banners.php page due to inadequate protection against certain types of attacks. The only security measure in place is the removal of SCRIPT tags, which can be bypassed by using HTML event handlers to execute JavaScript code. This allows a malicious actor to exploit the issue.
Recommendations For PHP-Fusion version 9.03.50, consider disabling access to the banners.php page until a proper fix is implemented to prevent the exploitation of this issue. Additionally, restricting the use of HTML event handlers in this context can serve as a temporary mitigation measure.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12438

Affected Products

Php-Fusion