SQL Injection Vulnerability in PHP-Fusion by PHP-Fusion Inc.
CVE-2013-7375

Currently unrated

Key Information:

Vendor

PHP-fusion

Vendor
CVE Published:
5 May 2014

What is CVE-2013-7375?

A vulnerability exists in PHP-Fusion versions 7.02.01 through 7.02.05, allowing remote attackers to execute arbitrary SQL commands through user IDs stored in cookies. This flaw, located in the Authenticate.class.php file, poses a risk by enabling unauthorized data manipulation, potentially leading to data breaches or system compromise.

References

EPSS Score

7% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.