SQL Injection Vulnerability in PHP-Fusion 9.03.50
CVE-2020-14960
7.2HIGH
Key Information:
- Vendor
PHP-fusion
- Status
- Vendor
- CVE Published:
- 22 June 2020
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2020-14960?
A SQL injection vulnerability exists in PHP-Fusion version 9.03.50, specifically impacting the endpoint administration/comments.php through the ctype parameter. This flaw can allow malicious actors to manipulate database queries, leading to unauthorized access or data disclosure.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
