Description
|
|
Multiple vulnerabilities were identified in PHP-Fusion, which could be exploited by malicious users to conduct cross site scripting attacks or gain unauthorized access.
- The first issue is due to an input validation error in the "submit.php" file when processing specially crafted "news_body", "article_description", and "article_body" parameters, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser.
- The second vulnerability resides in the "administration/db_backups/" directory that does not properly verify security permissions, which could be exploited by remote attackers to download the database.
|