Description
A stored cross site scripting (XSS) vulnerability in /administration/settings_registration.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Registration" field.
Remediation
References
Related Vulnerabilities
Payara Files or Directories Accessible to External Parties Vulnerability (CVE-2022-45129)
WordPress Plugin Image Photo Gallery Final Tiles Grid Cross-Site Scripting (3.4.18)
WordPress Plugin eCommerce Product Catalog for WordPress Cross-Site Request Forgery (2.9.43)
e107 Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-1989)