Description
A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Registration" field.
Remediation
References
Related Vulnerabilities
Plone CMS URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2020-7936)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.5.18.727)
Apache Tomcat Always-Incorrect Control Flow Implementation Vulnerability (CVE-2026-53404)
Liferay DXP Observable Discrepancy Vulnerability (CVE-2024-26268)