PT-2026-6591 · Unknown · Php-Fusion
Unkn0Wn
·
Published
2026-02-05
·
Updated
2026-02-05
·
CVE-2020-37152
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHP-Fusion version 9.03.50
Description
The application does not properly sanitize user input before rendering it in a browser, which allows attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted input to the
panel content POST parameter in the ''panels.php'' file, resulting in the execution of malicious scripts within the context of the affected site.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php-Fusion