PHPFusion 9.03.110 is affected by cross-site scripting (XSS) in the preg patterns filter html tag without "//" in descript() function An authenticated user can trigger XSS by appending "//" in the end of text.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-11T13:16:45

Updated: 2024-08-04T02:44:10.845Z

Reserved: 2021-09-07T00:00:00

Link: CVE-2021-40541

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-11T14:15:07.647

Modified: 2024-11-21T06:24:21.460

Link: CVE-2021-40541

cve-icon Redhat

No data.