PT-2021-10940 · Unknown · Php-Fusion
Published
2021-11-02
·
Updated
2021-11-03
·
CVE-2020-23754
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
PHP-Fusion version 9.03.50
Description:
The issue is related to a Cross Site Scripting (XSS) vulnerability, which allows attackers to execute arbitrary code via the polls feature. This is made possible through the
poll admin.php file in the infusions/member poll panel directory.Recommendations:
For PHP-Fusion version 9.03.50, consider disabling the polls feature until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to the
poll admin.php file to minimize the risk of arbitrary code execution.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php-Fusion