Vulnerability Description
CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php-Fusion | Phpfusion | 9.03.110 |
Related Weaknesses (CWE)
References
- https://anotepad.com/notes/2skndaytExploitThird Party Advisory
- https://github.com/PHPFusion/PHPFusion/commit/08d6c2ea49bd06fcce32275252f5f25abePatchThird Party Advisory
- https://github.com/PHPFusion/PHPFusion/commit/1c2b32321cf11ed1cd3ff835f8da0d172cPatchThird Party Advisory
- https://github.com/PHPFusion/PHPFusion/commit/da9f89ae70219f357fba6fffd2dae1ec88PatchThird Party Advisory
- https://github.com/PHPFusion/PHPFusion/commit/fda266c3bb35c650a8c4c51b6923abdfb6PatchThird Party Advisory
- https://anotepad.com/notes/2skndaytExploitThird Party Advisory
- https://github.com/PHPFusion/PHPFusion/commit/08d6c2ea49bd06fcce32275252f5f25abePatchThird Party Advisory
- https://github.com/PHPFusion/PHPFusion/commit/1c2b32321cf11ed1cd3ff835f8da0d172cPatchThird Party Advisory
- https://github.com/PHPFusion/PHPFusion/commit/da9f89ae70219f357fba6fffd2dae1ec88PatchThird Party Advisory
- https://github.com/PHPFusion/PHPFusion/commit/fda266c3bb35c650a8c4c51b6923abdfb6PatchThird Party Advisory
FAQ
What is CVE-2021-28280?
CVE-2021-28280 is a vulnerability with a CVSS score of 6.1 (MEDIUM). CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML
How severe is CVE-2021-28280?
CVE-2021-28280 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-28280?
Check the references section above for vendor advisories and patch information. Affected products include: Php-Fusion Phpfusion.