Description PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php. Remediation References CVE-2020-23658 Related Vulnerabilities Squid Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2016-4054) WordPress Plugin SecureMoz Security Audit PHP Object Injection (1.0.5) phpMyFAQ Weak Password Requirements Vulnerability (CVE-2023-0793) ATutor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-7172) Ruby on Rails CVE-2018-16477 Vulnerability (CVE-2018-16477) Severity Medium Classification CVE-2020-23658 CWE-707 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities