First published: Wed Jan 13 2021(Updated: )
PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Phpfusion | =9.03.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35687 refers to a vulnerability in PHPFusion version 9.03.90 that allows an attacker to perform a CSRF attack leading to the deletion of all shoutbox messages.
CVE-2020-35687 has a severity rating of 4.3, which is considered medium.
PHPFusion version 9.03.90 is affected by CVE-2020-35687.
Yes, you can find references for CVE-2020-35687 at the following links: [GitHub issue](https://github.com/PHPFusion/PHPFusion/issues/2347) and [Exploit-DB](https://www.exploit-db.com/exploits/49426).
At the time of writing, there is no official fix available for CVE-2020-35687. It is recommended to update to a newer version of PHPFusion when a patch becomes available.