r90tpass

1 exploit Active since Sep 2020
CVE-2020-24949 NOMISEC HIGH WORKING POC
php-fusion 9.03.50 - Authenticated Remote Code Execution via Downloads Endpoint
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).
CVSS 8.8