PHPFusion 9.03.50 contains a persistent cross-site scripting vulnerability in the print.php page that fails to properly sanitize user-submitted message content. Attackers can inject malicious JavaScript through forum messages that will execute when the print page is generated, allowing script execution in victim browsers.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-30 17:16
Updated : 2026-01-30 17:16
NVD link : CVE-2020-36996
Mitre link : CVE-2020-36996
CVE.ORG link : CVE-2020-36996
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
