Description PHP-Fusion 9.03 allows XSS on the preview page. Remediation References CVE-2020-17450 Related Vulnerabilities WordPress Plugin Amministrazione Trasparente Cross-Site Request Forgery (7.1) IBM RTC Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-20352) XWiki Missing Authorization Vulnerability (CVE-2022-41930) WordPress Plugin Zingiri Web Shop 'abspath' Parameter Remote File Include (2.4.6) WordPress 4.2.x Same Origin Method Execution (SOME) Vulnerability (4.2 - 4.2.7) Severity Medium Classification CVE-2020-17450 CWE-707 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities