Description
A stored cross site scripting (XSS) vulnerability in /administration/setting_security.php of PHP-Fusion 9.03.60 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload.
Remediation
References
Related Vulnerabilities
WordPress Plugin myTreasures Cross-Site Scripting (2.4.10)
WordPress Plugin Numbers generator and validator Multiple Unspecified Vulnerabilities (1.02)
WordPress Plugin SEO Backlinks Cross-Site Request Forgery (4.0.1)
WordPress Plugin WP GuestMap Multiple Cross-Site Scripting Vulnerabilities (1.8)
WordPress Plugin Default Facebook Thumbnails Multiple Vulnerabilities (0.4)