CVE-2022-3152: Unverified Password Change in phpfusion/phpfusion
Published Sep 7, 2022
·Updated
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
Affected Software
1 affected component
PHP-Fusion Phpfusion<9.10.20
Remediation
Event History
Sep 7, 2022
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-3152?
CVE-2022-3152 is a vulnerability in the GitHub repository phpfusion/phpfusion prior to version 9.10.20 that allows for an unverified password change.
2
What is the severity of CVE-2022-3152?
CVE-2022-3152 has a severity rating of critical with a value of 8.8.
3
How does CVE-2022-3152 affect Php-fusion Phpfusion?
CVE-2022-3152 affects Php-fusion Phpfusion versions up to and excluding 9.10.20.
4
How can I fix CVE-2022-3152?
To fix CVE-2022-3152, update your Php-fusion Phpfusion installation to version 9.10.20 or later.
5
What are the references for CVE-2022-3152?
For more information on CVE-2022-3152, you can visit the following references: [GitHub Commit](https://github.com/phpfusion/phpfusion/commit/57c96d4a0c00e8e1e25100087654688123c6e991) and [Huntr.dev Bounty](https://huntr.dev/bounties/b3f888d2-5c71-4682-8287-42613401fd5a).