QID 730954

Date Published: 2023-10-25

QID 730954: Fusion Hypertext Preprocessor (PHP) Local File Inclusion in Forum Infusion Vulnerability

PHP-Fusion is a free and open-source web framework based on PHP

Affected Version
PHPFusion 9.10.30 and earlier versions.
QID detection logic (Un-Auth)
This qid send GET request to "/fusion/index.php" to check software version

Exploitation of this vulnerability can lead to remote code execution (RCE) if an attacker can acquire some means of uploading a crafted payload file with the .php extension to any known absolute path on the target system.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Please refer to PHP advisory: cve-2023-2453 for patching details

    CVEs related to QID 730954

    Software Advisories
    Advisory ID Software Component Link