Description
A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field.
Remediation
References
Related Vulnerabilities
WordPress Plugin BingImport Cross-Site Scripting (0.4)
WordPress Plugin Membership Simplified Multiple SQL Injection Vulnerabilities (1.58)
WordPress Plugin GiveWP-Donation and Fundraising Platform Cross-Site Scripting (2.9.7)
WordPress Plugin Email Verification for WooCommerce Unspecified Vulnerability (1.8.1)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2021-32566)