Multiple Cross-Site Scripting Issues in PHP-Fusion by PHP-Fusion
CVE-2020-12708

6.1MEDIUM

Key Information:

Vendor

PHP-fusion

Vendor
CVE Published:
7 May 2020

What is CVE-2020-12708?

PHP-Fusion version 9.03.50 contains multiple cross-site scripting vulnerabilities that can be exploited by remote attackers. By injecting arbitrary web scripts or HTML code through the 'cat_id' parameter in 'downloads/downloads.php' or 'article.php', attackers can compromise the integrity of the website and potentially gain unauthorized access to user data. It is crucial for administrators to apply security updates and mitigate these risks to protect their online platforms.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.