CVE-2020-24949
PHP-Fusion 9.03.50 downloads/downloads.php Authenticated Remote Code Execution
Record summary
CVE-2020-24949 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.
Description
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
php-fusionBrowse php-fusion / php-fusion | VulnCheck | Version data not supplied | |
Proofs of concept
2Catalogued exploits
ExploitDBPHPFusion 9.03.50 - Remote Code ExecutionExploitDB exploitby g0ldm45kNot analyzed1 file
Repository PoCs
GitHubr90tpass/CVE-2020-24949Repository PoCby r90tpassStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHPHP-Fusion 9.03.50 - Remote Code ExecutionCVSS 8.8
PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution.
Impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the affected system, potentially leading to full compromise.
Remediation
Apply the latest security patch or upgrade to a non-vulnerable version of PHP-Fusion.
Source: ProjectDiscovery