PHPFusion
cpe:2.3:a:php-fusion:phpfusion:*:*:*:*:*:*:*
- 9.10.30
A stored cross-site scripting vulnerability has been identified in PHPFusion version 9.10.30. This issue resides within the file manager, where attackers can upload malicious SVG files containing embedded JavaScript. Once uploaded, the JavaScript can execute when the SVG file is viewed, potentially leading to the theft of user session information or other client-side attacks.
Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded SVG files execute JavaScript in the context of the user viewing the file.
To reproduce this vulnerability, upload a malicious SVG file containing JavaScript into the PHPFusion file manager. After uploading, the JavaScript will execute when the SVG file is accessed through the administration images page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.