CVE-2019-12099
HIGHPHP- Fusion 9.03.00 - RCE
Title source: llmDescription
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload.
Exploits (1)
References (3)
Scores
CVSS v3
8.8
EPSS
0.4050
EPSS Percentile
97.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (1)
php-fusion/php-fusion
< 9.03.00
Published
May 14, 2019
Tracked Since
Feb 18, 2026