peter bassill · operator
$ cve CVE-2020-35687 JSON

CVE-2020-35687 EXPLOIT

4.3
MEDIUM · CVSS 3.1 · EPSS 1.4% (pctl 71)

Patch early

A public exploit exists.

Description

PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

Scoring

CVSS4.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
EPSS1.38% — more likely to be exploited than 71% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2021-01-13
Last modified2026-06-17

Affected (1)

VendorProduct
php-fusionphpfusion

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD