PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-12706 - Vulnerability Database

PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-12706

Medium
Reference: CVE-2020-12706
Title: PHP-Fusion Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Multiple Cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the go parameter to faq/faq_admin.php or shoutbox_panel/shoutbox_admin.php