Cross Site Scripting Vulnerability in PHP-Fusion Shoutbox Panel
CVE-2020-23702
4.8MEDIUM
What is CVE-2020-23702?
A Cross Site Scripting (XSS) vulnerability has been identified in PHP-Fusion 9.03.60 within the 'New Shout' feature of the shoutbox functionality. This flaw allows attackers to inject malicious scripts into the system, which can be executed by unsuspecting users who visit the affected area of the application. Proper validation and sanitization of user inputs in the shoutbox admin panel are essential to mitigate potential risks associated with this vulnerability.