Description
An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags.
Remediation
References
Related Vulnerabilities
Magento Insufficient Verification of Data Authenticity Vulnerability (CVE-2019-8124)
MySQL CVE-2013-1544 Vulnerability (CVE-2013-1544)
Chamilo Improper Input Validation Vulnerability (CVE-2021-31933)
WordPress 5.5.x Multiple Vulnerabilities (5.5 - 5.5.11)
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud Security Bypass (3.9.2)