← Vulnerability feed

Vulnerability record · CVE-2020-24949 · published 3 September 2020

CVE-2020-24949: PHP-Fusion downloads.php privilege escalation to RCE

Php Fusion · Php Fusion

PHP-Fusion 9.03.50 contains a privilege escalation flaw in downloads/downloads.php that lets an authenticated non-admin user send a crafted request and achieve remote command execution. Because the attacker only needs a low-privileged account, the flaw turns ordinary forum or site membership into a path to full server compromise.

8.8 CVSS 3.1 High EPSS 68% · top 0.7%
8.8CVSS 3.1 base score, v2 9.0
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw allows authenticated non-admin users to reach remote code execution, public exploit code exists, and EPSS is very high, though it is not in KEV and requires a valid account.

What it is

PHP-Fusion 9.03.50 contains a privilege escalation flaw in downloads/downloads.php that lets an authenticated non-admin user send a crafted request and achieve remote command execution. Because the attacker only needs a low-privileged account, the flaw turns ordinary forum or site membership into a path to full server compromise.

Impact

An authenticated non-admin attacker can execute arbitrary commands on the server, gaining control of the web application and potentially the underlying host. This can lead to data theft, defacement, or use of the server as a foothold for further attacks.

Attack surface

The flaw is reached over the network through the downloads/downloads.php endpoint. It requires a valid authenticated account but no admin rights and no user interaction beyond sending the crafted request.

Exploitation

Public exploit code is referenced in Packet Storm and the PHP-Fusion GitHub issue, and EPSS is high at roughly 0.675 (99th percentile), though the CVE is not listed in CISA KEV and no ransomware use is documented.

What to do

  • Upgrade PHP-Fusion to a version that fixes the downloads.php privilege escalation; if no fixed release is available, apply the vendor patch or commit referenced in the GitHub issue.
  • Restrict or disable the downloads module until patched, and remove untrusted accounts that could reach it.
  • Enforce least privilege and review non-admin roles so low-privileged users cannot reach administrative or file-handling functionality.
  • Deploy a WAF rule to block crafted requests to downloads/downloads.php and monitor for command injection patterns.
  • Audit the server for signs of compromise and rotate credentials and secrets if exploitation is suspected.

Detection

  • Monitor web logs for unusual POST or GET requests to downloads/downloads.php, especially from non-admin sessions.
  • Alert on command execution or shell-related child processes spawned by the web server user.
  • Look for unexpected file writes or new files in web-accessible directories following downloads module activity.
  • Correlate authenticated low-privilege user activity with outbound network connections or privilege changes on the host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-24949 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4931Php-fusion path traversal vulnerabilityDirectory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary local files via a .. (dot do…EPSS 16%8.8CVE-2020-12461Php-fusion sql injection vulnerabilityPHP-Fusion 9.03.50 allows SQL Injection because maincore.php has an insufficient protection mechanism. An attacker can develop a crafted payload that…EPSS 1.7%8.8CVE-2019-12099Php-fusion unrestricted file upload vulnerabilityIn PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dynamics/includes/form_fileinput…EPSS 17%8.1CVE-2021-3172Php-fusion incorrect permission assignment vulnerabilityAn issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Service via the Polling feature.EPSS 0.65%7.5CVE-2014-8596Php-fusion sql injection vulnerabilityMultiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id…EPSS 3.3%7.5CVE-2013-7375Php-fusion sql injection vulnerabilitySQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbit…EPSS 3.6%7.5CVE-2013-1803Php-fusion sql injection vulnerabilityMultiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby para…EPSS 4.0%7.5CVE-2008-5946Php-fusion sql injection vulnerabilitySQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.EPSS 0.96%

Source: NIST National Vulnerability Database (record CVE-2020-24949), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.