CVE-2020-35952: Medium severity jenkins vulnerability
login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect username or password" message in both cases), which might allow enumeration.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35952?
CVE-2020-35952 is a vulnerability in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 that allows enumeration through error messages generated by the login.php file.
How does CVE-2020-35952 impact PHPFusion?
CVE-2020-35952 impacts PHPFusion by allowing an attacker to determine whether a username or password is incorrect through different error messages generated by the login.php file.
What is the severity of CVE-2020-35952?
CVE-2020-35952 has a severity rating of medium (6.5).
How can I fix CVE-2020-35952?
To fix CVE-2020-35952, upgrade PHPFusion to Andromeda 9.x version 2020-12-30 or later.
Where can I find more information about CVE-2020-35952?
More information about CVE-2020-35952 can be found in the GitHub issue at https://github.com/PHPFusion/PHPFusion/issues/2346.