First published: Sun Jan 03 2021(Updated: )
login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect username or password" message in both cases), which might allow enumeration.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php-fusion Php-fusion | >=9.0<9.03.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35952 is a vulnerability in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 that allows enumeration through error messages generated by the login.php file.
CVE-2020-35952 impacts PHPFusion by allowing an attacker to determine whether a username or password is incorrect through different error messages generated by the login.php file.
CVE-2020-35952 has a severity rating of medium (6.5).
To fix CVE-2020-35952, upgrade PHPFusion to Andromeda 9.x version 2020-12-30 or later.
More information about CVE-2020-35952 can be found in the GitHub issue at https://github.com/PHPFusion/PHPFusion/issues/2346.