Vulnerability Description
An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Php-Fusion | Php-Fusion | >= 9.03.90, < 9.10.00 |
Related Weaknesses (CWE)
References
- https://github.com/PHPFusion/PHPFusion/commit/7b8df6925cc7cfd8585d4f34d9120ff3a2Patch
- https://github.com/PHPFusion/PHPFusion/issues/2351ExploitIssue TrackingThird Party Advisory
- https://github.com/PHPFusion/PHPFusion/commit/7b8df6925cc7cfd8585d4f34d9120ff3a2Patch
- https://github.com/PHPFusion/PHPFusion/issues/2351ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2021-3172?
CVE-2021-3172 is a vulnerability with a CVSS score of 8.1 (HIGH). An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature.
How severe is CVE-2021-3172?
CVE-2021-3172 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3172?
Check the references section above for vendor advisories and patch information. Affected products include: Php-Fusion Php-Fusion.