Remote Code Execution Vulnerability in PHP-Fusion by PHP-Fusion
CVE-2019-12099

8.8HIGH

Key Information:

Vendor

PHP-fusion

Vendor
CVE Published:
14 May 2019

What is CVE-2019-12099?

In PHP-Fusion version 9.03.00, a vulnerability exists in the edit_profile.php script that allows remote authenticated users to execute arbitrary code. This is primarily due to a flaw in the handling of executable files during the avatar upload process, specifically within the form_fileinput.php and Core.settings.inc files. If exploited, this could potentially allow attackers to execute malicious code on the server, posing significant risk to the integrity and security of the affected system.

References

EPSS Score

42% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.