PHPFusion Stored Cross-Site Scripting Vulnerability in File Manager

Vulnerability

A stored cross-site scripting vulnerability has been identified in PHPFusion version 9.10.30. This issue resides within the file manager, where attackers can upload malicious SVG files containing embedded JavaScript. Once uploaded, the JavaScript can execute when the SVG file is viewed, potentially leading to the theft of user session information or other client-side attacks.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded SVG files execute JavaScript in the context of the user viewing the file.

Reproduction

To reproduce this vulnerability, upload a malicious SVG file containing JavaScript into the PHPFusion file manager. After uploading, the JavaScript will execute when the SVG file is accessed through the administration images page.

Added: Dec 17, 2025, 11:31 PM
Updated: Dec 17, 2025, 11:31 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
6.5
remediation
0.0
relevance
1.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.