PT-2021-11884 · Php Fusion · Php-Fusion

Oosman-Rako

·

Published

2021-01-03

·

Updated

2021-01-11

·

CVE-2020-35952

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: PHPFusion (aka PHP-Fusion) Andromeda versions 9.x before 2020-12-30
Description: The issue arises from the login.php file generating distinct error messages for incorrect usernames and passwords, rather than a unified message. This distinction might allow for enumeration.
Recommendations: For PHPFusion (aka PHP-Fusion) Andromeda versions 9.x before 2020-12-30, update to a version released after 2020-12-30 to resolve the issue. As a temporary workaround, consider modifying the login.php file to display a single, unified error message for both incorrect usernames and passwords, thus preventing potential enumeration.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-35952

Affected Products

Php-Fusion