PT-2020-13226 · Php Fusion · Php-Fusion

Published

2020-05-07

·

Updated

2020-05-14

·

CVE-2020-12718

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHP-Fusion version 9.03.50
Description The issue concerns a stored XSS vulnerability in the Preview Comment feature of the administration/comments.php file. An authenticated attacker can exploit this by bypassing the protection mechanism using HTML event handlers such as ontoggle.
Recommendations For PHP-Fusion version 9.03.50, as a temporary workaround, consider disabling the Preview Comment feature until a patch is available. Restrict access to the administration/comments.php file to minimize the risk of exploitation. Avoid using HTML event handlers in the Preview Comment feature until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12718

Affected Products

Php-Fusion