Vulnerabilities
33 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-37137 +1 in the same advisory: …37152 | PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php administration endpoint to execute malicious code. NVD description · AI analysis pending | 8.6 group max | <1% | PoC |
| — | |
| CVE-2023-53928 | PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded Jav PHPFusion 9.10.30 contains a stored cross-site scripting vulnerability in the file manager that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload SVG files with script tags that execute arbitrary JavaScript when viewed, potentially stealing user session information or performing client-side attacks. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2023-2453 +1 in the same advisory: …4480 | There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary files with the ‘.php’ extension for which the absolute path is known to be included and executed. There are no known means in PHPFusion through which an attacker can upload and target a ‘.php’ file payload. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2021-3172 | An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature. An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature. NVD description · AI analysis pending | 8.1 | <1% | PoC |
| — | |
| CVE-2022-3152 | Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20. Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2020-23754 | Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via th Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature. NVD description · AI analysis pending | 9.6 | 2% |
| — | ||
| CVE-2021-40189 | PHPFusion 9.03.110 is affected by a remote code execution vulnerability. PHPFusion 9.03.110 is affected by a remote code execution vulnerability. The theme function will extract a file to "webroot/themes/{Theme Folder], where an attacker can access and execute arbitrary code. NVD description · AI analysis pending | 7.2 group max | 2% | PoC |
| — | |
| CVE-2020-23702 | Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php. Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php. NVD description · AI analysis pending | 4.8 | <1% | PoC ×2 |
| — | |
| CVE-2020-23178 | An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack an An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2021-28280 | CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML CSRF + Cross-site scripting (XSS) vulnerability in search.php in PHPFusion 9.03.110 allows remote attackers to inject arbitrary web script or HTML NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2020-35687 | PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim. PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim. NVD description · AI analysis pending | 4.3 | 1% | PoC ×2 |
| — | |
| CVE-2020-35952 | login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect passw login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect username or password" message in both cases), which might allow enumeration. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2020-24949 | Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE). NVD description · AI analysis pending | 8.8 | 68% | PoC ×2 |
| — | |
| CVE-2020-23658 | PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php. PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-17450 +1 in the same advisory: …17449 | PHP-Fusion 9.03 allows XSS on the preview page. PHP-Fusion 9.03 allows XSS on the preview page. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2020-15041 | PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field. PHP-Fusion 9.03.60 allows XSS via the administration/site_links.php Add Site Link field. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2020-14960 | A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter, A SQL injection vulnerability in PHP-Fusion 9.03.50 affects the endpoint administration/comments.php via the ctype parameter, NVD description · AI analysis pending | 7.2 | 2% | PoC ×2 |
| — | |
| CVE-2020-12718 | In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-12708 +1 in the same advisory: …12706 | Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to do Multiple cross-site scripting vulnerabilities in PHP-Fusion 9.03.50 allow remote attackers to inject arbitrary web script or HTML via the cat_id parameter to downloads/downloads.php or article.php. NOTE: this might overlap CVE-2012-6043. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — | |
| CVE-2020-12461 | PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. PHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that can be inserted into the sort_order GET parameter on the members.php members search page. This parameter allows for control over anything after the ORDER BY clause in the SQL query. NVD description · AI analysis pending | 8.8 | 2% | PoC ×2 |
| — | |
| CVE-2020-12438 | An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. An XSS vulnerability exists in the banners.php page of PHP-Fusion 9.03.50. This can be exploited because the only security measure used against XSS is the stripping of SCRIPT tags. A malicious actor can use HTML event handlers to run JavaScript instead of using SCRIPT tags. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2019-12099 | In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and in In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload. NVD description · AI analysis pending | 8.8 | 17% | PoC ×2 |
| — |