CVE-2020-35687 EXPLOIT
4.3
MEDIUM · CVSS 3.1 · EPSS 1.4% (pctl 71)
Patch early
A public exploit exists.
Description
PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.
Scoring
| CVSS | 4.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
| EPSS | 1.38% — more likely to be exploited than 71% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-01-13 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| php-fusion | phpfusion |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PHP-Fusion CMS 9.03.90 - Cross-Site Request Forgery (Delete admin shoutbox message) | 2021-01-15 |
References
→ the Explorer · watch your stack · NVD