216.73.217.22

CVE-2020-37137

· Published 05/02/2026 17:16 · Modified 05/02/2026 20:47

Labels: CVE-2020-37137 2026-02-05CVE-2020-37137CWE-95[email protected]

Essential information

Published
05/02/2026 17:16
Modified
05/02/2026 20:47
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php administration endpoint to execute malicious code.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
php-fusion / php-fusion cpe:2.3:a:php-fusion:php-fusion:9.03.50:*:*:*:*:*:*:*

References