PT-2021-10940 · Unknown · Php-Fusion

Published

2021-11-02

·

Updated

2021-11-03

·

CVE-2020-23754

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: PHP-Fusion version 9.03.50
Description: The issue is related to a Cross Site Scripting (XSS) vulnerability, which allows attackers to execute arbitrary code via the polls feature. This is made possible through the poll admin.php file in the infusions/member poll panel directory.
Recommendations: For PHP-Fusion version 9.03.50, consider disabling the polls feature until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to the poll admin.php file to minimize the risk of arbitrary code execution.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23754

Affected Products

Php-Fusion