CVE-2020-24949: Critical severity jenkins vulnerability
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24949?
CVE-2020-24949 is a vulnerability in PHP-Fusion 9.03.50 downloads/downloads.php that allows an authenticated user (not admin) to perform remote command execution (RCE).
How severe is CVE-2020-24949?
CVE-2020-24949 has a severity rating of 8.8 (critical).
Which version of PHP-Fusion is affected by CVE-2020-24949?
PHP-Fusion 9.03.50 is the affected version.
What can an authenticated user do with CVE-2020-24949?
An authenticated user (not admin) can send a crafted request to the server and perform remote command execution (RCE).
Are there any references related to CVE-2020-24949?
Yes, there are references available at these URLs: [http://packetstormsecurity.com/files/162852/PHPFusion-9.03.50-Remote-Code-Execution.html](http://packetstormsecurity.com/files/162852/PHPFusion-9.03.50-Remote-Code-Execution.html), [https://github.com/php-fusion/PHP-Fusion/issues/2312](https://github.com/php-fusion/PHP-Fusion/issues/2312).