Description
A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Registration" field.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Mobile Pack Information Disclosure (2.1.2)
WordPress Plugin Welcart e-Commerce Multiple Vulnerabilities (1.4.17)
Dotclear Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-1613)
Oracle Database Server CVE-2006-1870 Vulnerability (CVE-2006-1870)
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud Security Bypass (4.14.7)