Vulnerability Description
PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php-Fusion | Phpfusion | 9.03.90 |
Related Weaknesses (CWE)
References
- https://github.com/PHPFusion/PHPFusion/issues/2347ExploitIssue TrackingThird Party Advisory
- https://www.exploit-db.com/exploits/49426ExploitThird Party AdvisoryVDB Entry
- https://github.com/PHPFusion/PHPFusion/issues/2347ExploitIssue TrackingThird Party Advisory
- https://www.exploit-db.com/exploits/49426ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2020-35687?
CVE-2020-35687 is a vulnerability with a CVSS score of 4.3 (MEDIUM). PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.
How severe is CVE-2020-35687?
CVE-2020-35687 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35687?
Check the references section above for vendor advisories and patch information. Affected products include: Php-Fusion Phpfusion.