Cross Site Scripting Vulnerability in PHP-Fusion Shoutbox Panel
CVE-2020-23702

4.8MEDIUM

Key Information:

Vendor

PHP-fusion

Vendor
CVE Published:
7 July 2021

What is CVE-2020-23702?

A Cross Site Scripting (XSS) vulnerability has been identified in PHP-Fusion 9.03.60 within the 'New Shout' feature of the shoutbox functionality. This flaw allows attackers to inject malicious scripts into the system, which can be executed by unsuspecting users who visit the affected area of the application. Proper validation and sanitization of user inputs in the shoutbox admin panel are essential to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.