Vulnerability record · CVE-2020-24949 · published 3 September 2020
CVE-2020-24949: PHP-Fusion downloads.php privilege escalation to RCE
Php Fusion · Php Fusion
PHP-Fusion 9.03.50 contains a privilege escalation flaw in downloads/downloads.php that lets an authenticated non-admin user send a crafted request and achieve remote command execution. Because the attacker only needs a low-privileged account, the flaw turns ordinary forum or site membership into a path to full server compromise.
Description
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server and perform remote command execution (RCE).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows authenticated non-admin users to reach remote code execution, public exploit code exists, and EPSS is very high, though it is not in KEV and requires a valid account.
What it is
PHP-Fusion 9.03.50 contains a privilege escalation flaw in downloads/downloads.php that lets an authenticated non-admin user send a crafted request and achieve remote command execution. Because the attacker only needs a low-privileged account, the flaw turns ordinary forum or site membership into a path to full server compromise.
Impact
An authenticated non-admin attacker can execute arbitrary commands on the server, gaining control of the web application and potentially the underlying host. This can lead to data theft, defacement, or use of the server as a foothold for further attacks.
Attack surface
The flaw is reached over the network through the downloads/downloads.php endpoint. It requires a valid authenticated account but no admin rights and no user interaction beyond sending the crafted request.
Exploitation
Public exploit code is referenced in Packet Storm and the PHP-Fusion GitHub issue, and EPSS is high at roughly 0.675 (99th percentile), though the CVE is not listed in CISA KEV and no ransomware use is documented.
What to do
- Upgrade PHP-Fusion to a version that fixes the downloads.php privilege escalation; if no fixed release is available, apply the vendor patch or commit referenced in the GitHub issue.
- Restrict or disable the downloads module until patched, and remove untrusted accounts that could reach it.
- Enforce least privilege and review non-admin roles so low-privileged users cannot reach administrative or file-handling functionality.
- Deploy a WAF rule to block crafted requests to downloads/downloads.php and monitor for command injection patterns.
- Audit the server for signs of compromise and rotate credentials and secrets if exploitation is suspected.
Detection
- Monitor web logs for unusual POST or GET requests to downloads/downloads.php, especially from non-admin sessions.
- Alert on command execution or shell-related child processes spawned by the web server user.
- Look for unexpected file writes or new files in web-accessible directories following downloads module activity.
- Correlate authenticated low-privilege user activity with outbound network connections or privilege changes on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162852/PHPFusion-9.03.50-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/php-fusion/PHP-Fusion/issues/2312 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/162852/PHPFusion-9.03.50-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/php-fusion/PHP-Fusion/issues/2312 | ExploitThird Party Advisory |
Track CVE-2020-24949 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-24949), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.