CVE-2020-35687

MEDIUM

PHPFusion 9.03.90 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-35687. PoCs published by Mohamed Oosman.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in PHP-Fusion CMS 9.03.90, allowing an attacker to delete shoutbox messages by tricking an admin into visiting a malicious link. The PoC uses a simple HTML form to submit a GET request with the required parameters.

Description

PHPFusion version 9.03.90 is vulnerable to CSRF attack which leads to deletion of all shoutbox messages by the attacker on behalf of the logged in victim.

Exploits (1)

exploitdb WORKING POC
by Mohamed Oosman · htmlwebappsphp
https://www.exploit-db.com/exploits/49426

This exploit demonstrates a CSRF vulnerability in PHP-Fusion CMS 9.03.90, allowing an attacker to delete shoutbox messages by tricking an admin into visiting a malicious link. The PoC uses a simple HTML form to submit a GET request with the required parameters.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: PHP-Fusion CMS 9.03.90 and below
Auth required
Prerequisites: Admin user must be logged in and visit the malicious link · Knowledge of the shout_id to delete
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/PHPFusion/PHPFusion/issues/2347
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49426

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 37.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-352
Status published
Products (1)
php-fusion/phpfusion 9.03.90
Published Jan 13, 2021
Tracked Since Feb 18, 2026