CVE-2020-24949: PHP-Fusion
High severity, CVSS 8.8. EPSS: 67.5% chance of exploitation in the next 30 days.
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).
Affected products
- PHP-Fusion PHP-Fusion: version 9.03.50 only
Published 2020-09-03. Last modified 2026-06-17.