CVE-2019-12099
HIGHphp-fusion < 9.03.00 - Authenticated Remote Code Execution via Avatar Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-12099. PoCs published by AkkuS.
AI-analyzed exploit summary This Metasploit module exploits a file upload vulnerability in PHP-Fusion < 9.03.00, allowing authenticated users to upload a malicious PHP file disguised as an avatar, leading to remote code execution.
Description
In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput.php and includes/classes/PHPFusion/Installer/Lib/Core.settings.inc mishandle executable files during avatar upload.
Exploits (1)
This Metasploit module exploits a file upload vulnerability in PHP-Fusion < 9.03.00, allowing authenticated users to upload a malicious PHP file disguised as an avatar, leading to remote code execution.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H