Description
PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated, allowing script execution in victim browsers.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
coiffeur
References
www.exploit-db.com/exploits/48497 (ExploitDB-48497)
www.php-fusion.co.uk/home.php (PHPFusion Official Homepage)
www.php-fusion.co.uk/php_fusion_9_downloads.php (PHPFusion Download Page)
www.vulncheck.com/...pfusion-persistent-cross-site-scripting (VulnCheck Advisory: PHPFusion 9.03.50 - Persistent Cross-Site Scripting)