User Enumeration Vulnerability in PHPFusion Andromeda 9.x
CVE-2020-35952

6.5MEDIUM

Key Information:

Vendor

PHP-fusion

Vendor
CVE Published:
3 January 2021

What is CVE-2020-35952?

The PHPFusion Andromeda 9.x version prior to December 30, 2020, presents a user enumeration vulnerability in its login.php component. This flaw allows attackers to differentiate between errors for incorrect usernames and passwords, thereby facilitating the enumeration of valid usernames. By exploiting this behavior, attackers can potentially gain insight into existing accounts, heightening the risk of unauthorized access or account compromise. It is crucial for users and administrators of PHPFusion to apply the necessary patches and implement additional security measures to mitigate the risk posed by this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.