PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-11T13:16:45

Updated: 2024-08-04T02:44:10.845Z

Reserved: 2021-09-07T00:00:00

Link: CVE-2021-40541

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-10-11T14:15:07.647

Modified: 2021-10-15T20:32:39.210

Link: CVE-2021-40541

cve-icon Redhat

No data.