PT-2020-6388 · Unknown · Php-Fusion
Songohan22
·
Published
2020-05-15
·
Updated
2021-07-06
·
CVE-2020-23181
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHP-Fusion version 9.03.60
Description
The issue is related to a reflected cross site scripting (XSS) vulnerability in the /administration/theme.php file of PHP-Fusion. This vulnerability can be exploited by authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the
Manage Theme field. The vulnerability exists due to insufficient protection of the web page structure.Recommendations
For PHP-Fusion version 9.03.60, consider disabling access to the /administration/theme.php file until a patch is available. Restrict access to the
Manage Theme field to minimize the risk of exploitation. Avoid using the Manage Theme field in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php-Fusion