CVE-2020-14960: SQL Injection
Published Jun 21, 2020
·Updated
A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,
Affected Software
1 affected component
PHP-Fusion php-fusion=9.03.50
Remediation
Event History
Jun 21, 2020
CVE Published
via MITRE·11:04 PM
Data Sourced
via MITRE·11:04 PM
Description
Frequently Asked Questions
1
What is CVE-2020-14960?
CVE-2020-14960 is a SQL injection vulnerability in PHP-Fusion 9.03.50 that affects the endpoint administration/comments.php.
2
How does CVE-2020-14960 affect PHP-Fusion?
CVE-2020-14960 affects PHP-Fusion 9.03.50 via the ctype parameter in the endpoint administration/comments.php, allowing SQL injection.
3
What is the severity of CVE-2020-14960?
CVE-2020-14960 has a severity rating of 7.2 (high).
4
How can I fix CVE-2020-14960?
To fix CVE-2020-14960, update PHP-Fusion to version 9.03.51 or later, which includes a patch for the vulnerability.
5
Where can I find more information about CVE-2020-14960?
You can find more information about CVE-2020-14960 on the official GitHub repository of PHP-Fusion and in the Exploit-DB entry.