VYPR
High severity8.8NVD Advisory· Published Sep 3, 2020· Updated Jun 17, 2026

CVE-2020-24949

CVE-2020-24949

Description

Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:php-fusion:php-fusion:9.03.50:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:php-fusion:php-fusion:9.03.50:*:*:*:*:*:*:*
    • (no CPE)range: 9.03.50
  • PHP-Fusion/PHP-Fusiondescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.