Description PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field. Remediation References CVE-2020-15041 Related Vulnerabilities Joomla! Core Information Disclosure (2.5.0 - 3.9.22) Oracle Database Server CVE-2014-6547 Vulnerability (CVE-2014-6547) WordPress Plugin Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list CSV Injection (2.0.68) WordPress Plugin Contact Form to DB by BestWebSoft Cross-Site Scripting (1.4.0) Atlassian Jira Other Vulnerability (CVE-2006-3338) Severity Medium Classification CVE-2020-15041 CWE-707 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Tags Missing Update Known Vulnerabilities