Description
A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
Remediation
References
Related Vulnerabilities
Apache Tomcat Improper Resource Shutdown or Release Vulnerability (CVE-2022-25762)
MediaWiki Improper Input Validation Vulnerability (CVE-2013-6453)
Jboss EAP Other Vulnerability (CVE-2023-3629)
MySQL CVE-2024-21212 Vulnerability (CVE-2024-21212)
WordPress Plugin uTubeVideo Gallery Cross-Site Scripting (2.0.7)