Vulnerability Description
login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect username or password" message in both cases), which might allow enumeration.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php-Fusion | Php-Fusion | >= 9.0, < 9.03.90 |
References
- https://github.com/PHPFusion/PHPFusion/issues/2346ExploitThird Party Advisory
- https://github.com/PHPFusion/PHPFusion/issues/2346ExploitThird Party Advisory
FAQ
What is CVE-2020-35952?
CVE-2020-35952 is a vulnerability with a CVSS score of 6.5 (MEDIUM). login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect usern...
How severe is CVE-2020-35952?
CVE-2020-35952 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-35952?
Check the references section above for vendor advisories and patch information. Affected products include: Php-Fusion Php-Fusion.