PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload SVG files with script tags that execute arbitrary JavaScript when viewed, potentially stealing user session information or performing client-side attacks.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/51411 | Exploit Third Party Advisory |
| https://www.phpfusion.com/index.php | Product |
| https://www.vulncheck.com/advisories/phpfusion-stored-cross-site-scripting-via-file-manager-upload | Third Party Advisory |
| https://www.exploit-db.com/exploits/51411 | Exploit Third Party Advisory |
Configurations
History
31 Dec 2025, 18:37
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:php-fusion:phpfusion:9.10.30:*:*:*:*:*:*:* | |
| References | () https://www.exploit-db.com/exploits/51411 - Exploit, Third Party Advisory | |
| References | () https://www.phpfusion.com/index.php - Product | |
| References | () https://www.vulncheck.com/advisories/phpfusion-stored-cross-site-scripting-via-file-manager-upload - Third Party Advisory | |
| First Time |
Php-fusion
Php-fusion phpfusion |
18 Dec 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/51411 - |
17 Dec 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-17 23:15
Updated : 2025-12-31 18:37
NVD link : CVE-2023-53928
Mitre link : CVE-2023-53928
CVE.ORG link : CVE-2023-53928
JSON object : View
Products Affected
php-fusion
- phpfusion
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
