CVE-2020-37137: PHP-Fusion 9.03.50 - 'panels.php' Eval Injection
PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'addpanelform()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panelcontent POST parameters to the panels.php administration endpoint to execute malicious code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37137?
CVE-2020-37137 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2020-37137?
To fix CVE-2020-37137, update PHP-Fusion to the latest version that addresses this vulnerability.
What systems are affected by CVE-2020-37137?
CVE-2020-37137 affects PHP-Fusion version 9.03.50.
Can CVE-2020-37137 be exploited remotely?
Yes, CVE-2020-37137 can be exploited remotely by sending crafted POST data.
What kind of vulnerability is CVE-2020-37137?
CVE-2020-37137 is classified as an eval injection vulnerability allowing arbitrary code execution.