Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

This top CMS has a major security flaw that could affect millions of websites

  • September 6, 2023
Total
0
Shares
0
0
0


PHPFusion, a top open-source content management system (CMS), carries multiple vulnerabilities that could put countless websites at risk, experts have warned.

A report from researchers at Synopsys, who discovered the flaws, described one of the vulnerabilities as an authenticated local file inclusion flaw, which is now tracked as CVE-2023-2453. It a hacker can upload a malicious php file to a known path on a target system, the flaw would allow them to run arbitrary code on a remote endpoint. 

The second vulnerability is a moderate-severity bug in the CMS that allows threat actors to read files and write them to arbitrary locations. This one is tracked as CVE-2023-4480. All PHPFusion versions up to 9.10.30 are vulnerable, the researchers added, stating that there is no patch available. To make matters worse, there seems to be no interest in fixing the flaws, whatsoever.

No patches in the pipeline

In a notification email sent to TechRadar Pro on behalf of Synopsys, it was said that there are currently “no patches available to fix the vulnerability, nor is the team aware of any plans by the project owners to create a patch.”

Synopsys said it tried to get to PHPFusion admins on numerous occasions, reaching out via email, vulnerability disclosure processes, GitHub, as well as community forums, to no avail. Finally, the team then decided to go public. PHPFusion is yet to respond to media inquiries.

The open-source CMS was built in 2003. Since then it’s gained provenance, amassing a user base of some 15 million strong (according to website data). Dark Reading reports that many small and medium-sized businesses use it to create online forums, community-driven websites, and more. 

To stay safe, it would be best to disable the “Forum” Infusion through the admin pane, the researchers added, knowing that in some cases that would shut down the entire website.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Ransomware gang claims credit for Sabre data breach

  • September 6, 2023
View Post
Next Article
  • Technology

Google Cloud’s CEO will discuss AI and what’s next at TechCrunch Disrupt 2023

  • September 6, 2023
View Post
You May Also Like
View Post
  • News

Amazon to Invest Up to $4 Billion in A.I. Start-Up Anthropic

  • September 26, 2023
View Post
  • News

Top Apple Executive Defends Favoring Google on iPhones

  • September 26, 2023
View Post
  • News

CMF by Nothing’s new Buds Pro and Watch Pro look like affordable bargains

  • September 26, 2023
View Post
  • News

This super-dangerous Android malware has returned to target US shoppers and bankers

  • September 26, 2023
View Post
  • News

Say goodbye to Google Podcasts, you’ll be forced to use YouTube Music by 2024

  • September 26, 2023
View Post
  • News

Microsoft Paint is getting its biggest upgrade in over a decade thanks to Windows Copilot

  • September 26, 2023
View Post
  • News

NFT marketplace OpenSea has been hacked, again

  • September 26, 2023
View Post
  • News

LG drops ATSC 3.0 4K tuners from its 2024 OLED TVs and Samsung or Sony could be next

  • September 26, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.