CVE-2020-35687

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
13/01/2021
Last modified:
02/02/2021

Description

PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:php-fusion:phpfusion:9.03.90:*:*:*:*:*:*:*