vendor:
Fusion News
by:
7.5
CVSS
HIGH
Command Execution
CWE
Product Name: Fusion News
Affected Version From: 3.6.2001
Affected Version To: 3.6.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Fusion News Administrator Command Execution Vulnerability
Fusion News is affected by an administrator command execution vulnerability. This allows a remote attacker to create a malicious URI link or embed a malicious URI between bbCode image tags, which includes hostile HTML and script code. If an unsuspecting forum administrator activates this URI, the attacker-supplied command would be carried out with the administrator's privileges.
Mitigation:
No known mitigation or remediation is currently available for this vulnerability.