Cross-Site Scripting in PHP-Fusion by PHP-Fusion Team
CVE-2020-15041
4.8MEDIUM
What is CVE-2020-15041?
The PHP-Fusion version 9.03.60 is susceptible to a Cross-Site Scripting (XSS) vulnerability, which occurs via the 'Add Site Link' feature in the administration panel. This flaw allows an attacker to inject malicious scripts into web pages viewed by other users, potentially compromising user data and session information.