PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php administration endpoint to execute malicious code.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerability by sending crafted panel_content POST parameters to the panels.php administration endpoint to execute malicious code. | |
| Title | PHP-Fusion 9.03.50 - 'panels.php' Eval Injection | |
| Weaknesses | CWE-95 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-05T16:13:37.832Z
Updated: 2026-02-05T20:37:15.390Z
Reserved: 2026-02-03T16:27:45.307Z
Link: CVE-2020-37137
Updated: 2026-02-05T20:37:04.685Z
Status : Awaiting Analysis
Published: 2026-02-05T17:16:09.003
Modified: 2026-02-05T20:47:37.777
Link: CVE-2020-37137
No data.