CVE-2020-37137
MEDIUMPHP-Fusion 9.03.50 - RCE
Title source: llmDescription
PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php administration endpoint to execute malicious code.
Exploits (1)
Scores
CVSS v3
6.1
EPSS
0.0007
EPSS Percentile
20.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-95
CWE-94
Status
published
Affected Products (1)
php-fusion/phpfusion
Timeline
Published
Feb 05, 2026
Tracked Since
Feb 18, 2026