Remote Code Execution Vulnerability in PHPFusion by PHPFusion
CVE-2021-40189
7.2HIGH
What is CVE-2021-40189?
PHPFusion 9.03.110 contains a vulnerability that allows remote code execution due to improper handling of theme functions. An attacker can exploit this flaw by uploading files to the webroot/theme directory, enabling unauthorized access and execution of arbitrary code on the server. Users of affected versions should act promptly to mitigate potential threats by applying necessary security patches.