ZeroHour

CVE-2020-35687

PoC ×2
CVSS 3.1
4.3 medium
EPSS
1%p70
Published
()
Modified
Description

PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

Vendors
php-fusion
Products
phpfusion
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.