HomePhp-FusionCVE-2020-35687

CVE-2020-35687

MEDIUM
4.3CVSS
Published: 2021-01-13
Updated: 2024-11-21
AI Analysis

Description

PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
none
Integrity
low
Availability
none
Weaknesses
CWE-352

Metadata

Primary Vendor
PHP-FUSION
Published
1/13/2021
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

php-fusion : phpfusion

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2020-35687 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com