HIGH
Unverified Password Change in phpfusion/phpfusion
Published Sep 7, 2022
8.8
HIGHCVSS 3.1
EPSS 0.88%
Description
Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
Affected products
-
Affected
- ≥ unspecified, < 9.10.20
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Phpfusion | Phpfusion/phpfusion | unknown | Affected
|
- < 9.10.20
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42576 Advisory
- https://github.com/phpfusion/phpfusion/commit/57c96d4a0c00e8e1e25100087654688123c6e991 x_refsource_MISCPatchThird Party Advisory
- https://huntr.dev/bounties/b3f888d2-5c71-4682-8287-42613401fd5a x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42576 | Advisory | |
| https://github.com/phpfusion/phpfusion/commit/57c96d4a0c00e8e1e25100087654688123c6e991 | x_refsource_MISCPatchThird Party Advisory | |
| https://huntr.dev/bounties/b3f888d2-5c71-4682-8287-42613401fd5a | x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Sep 7, 2022
Updated Aug 3, 2024
Reserved Sep 7, 2022
Link CVE-2022-3152
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data