Stored XSS Vulnerability in PHP-Fusion by PHP-Fusion
CVE-2020-12718
5.4MEDIUM
What is CVE-2020-12718?
In PHP-Fusion version 9.03.50, an authenticated attacker can exploit a stored cross-site scripting (XSS) vulnerability through the Preview Comment feature in administration/comments.php. This vulnerability allows attackers to bypass security mechanisms by utilizing HTML event handlers such as ontoggle, enabling the injection of malicious scripts that could lead to unauthorized actions or data exposure.