First published: Sun Jun 21 2020(Updated: )
A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter,
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Php-fusion | =9.03.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14960 is a SQL injection vulnerability in PHP-Fusion 9.03.50 that affects the endpoint administration/comments.php.
CVE-2020-14960 affects PHP-Fusion 9.03.50 via the ctype parameter in the endpoint administration/comments.php, allowing SQL injection.
CVE-2020-14960 has a severity rating of 7.2 (high).
To fix CVE-2020-14960, update PHP-Fusion to version 9.03.51 or later, which includes a patch for the vulnerability.
You can find more information about CVE-2020-14960 on the official GitHub repository of PHP-Fusion and in the Exploit-DB entry.