Vulnerability Description
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php-Fusion | Phpfusion | 9.03.50 |
Related Weaknesses (CWE)
References
- https://github.com/php-fusion/PHP-Fusion/issues/2315Broken Link
- https://user-images.githubusercontent.com/62001260/81574006-6fb70480-93cf-11ea-8Third Party Advisory
- https://user-images.githubusercontent.com/62001260/81574112-9412e100-93cf-11ea-9Third Party Advisory
- https://github.com/php-fusion/PHP-Fusion/issues/2315Broken Link
- https://user-images.githubusercontent.com/62001260/81574006-6fb70480-93cf-11ea-8Third Party Advisory
- https://user-images.githubusercontent.com/62001260/81574112-9412e100-93cf-11ea-9Third Party Advisory
FAQ
What is CVE-2020-23754?
CVE-2020-23754 is a vulnerability with a CVSS score of 9.6 (CRITICAL). Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.
How severe is CVE-2020-23754?
CVE-2020-23754 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-23754?
Check the references section above for vendor advisories and patch information. Affected products include: Php-Fusion Phpfusion.