CVE Database
/

CVE-2020-35952

Back to search

CVE-2020-35952

Published: Jan 3, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

login.php in PHPFusion (aka PHP-Fusion) Andromeda 9.x before 2020-12-30 generates error messages that distinguish between incorrect username and incorrect password (i.e., not a single "Incorrect username or password" message in both cases), which might allow enumeration.

VendorProductVersions

n/a

n/a

affected
n/a

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2020-35952 - Security Vulnerability | QwikSec