Description
A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Data Access Security Bypass (5.1.3)
Dolibarr Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-33816)
WordPress 4.3.x Multiple Vulnerabilities (4.3 - 4.3.8)
Moodle Incorrect Authorization Vulnerability (CVE-2022-0984)
MediaWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1581)