CVE-2020-24949

HIGH EXPLOITED NUCLEI

php-fusion 9.03.50 - Authenticated Remote Code Execution via Downloads Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-24949 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including g0ldm45k, r90tpass. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit leverages a command injection vulnerability in PHPFusion 9.03.50 via the `cat_id` parameter in the downloads module. It uses base64 encoding to bypass restrictions and executes a reverse shell payload if 'Allow PHP Execution' is enabled.

Description

Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

Exploits (2)

exploitdb WORKING POC VERIFIED
by g0ldm45k · pythonwebappsphp
https://www.exploit-db.com/exploits/49911

This exploit leverages a command injection vulnerability in PHPFusion 9.03.50 via the `cat_id` parameter in the downloads module. It uses base64 encoding to bypass restrictions and executes a reverse shell payload if 'Allow PHP Execution' is enabled.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: PHPFusion 9.03.50
No auth needed
Prerequisites: Target must have 'Allow PHP Execution' enabled · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by r90tpass · remote
https://github.com/r90tpass/CVE-2020-24949

This exploit leverages a command injection vulnerability in PHPFusion 9.03.50 via the `cat_id` parameter in the downloads module. It uses base64-encoded payloads to bypass restrictions and execute arbitrary commands, leading to remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: PHPFusion 9.03.50
No auth needed
Prerequisites: Target must have 'Allow PHP Execution' enabled · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

PHP-Fusion 9.03.50 - Remote Code Execution
HIGHby geeknik

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/php-fusion/PHP-Fusion/issues/2312
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/162852/PHPFusion-9.03.50-Remote-Code-Execution.html

Scores

CVSS v3 8.8
EPSS 0.6752
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2021-09-16
Status published
Products (1)
php-fusion/php-fusion 9.03.50
Published Sep 03, 2020
Tracked Since Feb 18, 2026