Multiple Cross-Site Scripting Issues in PHP-Fusion by PHP-Fusion
CVE-2020-12708
6.1MEDIUM
What is CVE-2020-12708?
PHP-Fusion version 9.03.50 contains multiple cross-site scripting vulnerabilities that can be exploited by remote attackers. By injecting arbitrary web scripts or HTML code through the 'cat_id' parameter in 'downloads/downloads.php' or 'article.php', attackers can compromise the integrity of the website and potentially gain unauthorized access to user data. It is crucial for administrators to apply security updates and mitigate these risks to protect their online platforms.