CVE-2020-37137 | PHP-Fusion 9.03.50 POST Parameter panels.php add_panel_form panel_content eval injection (Exploit 48278 / EUVD-2020-31029)
A vulnerability described as critical has been identified in PHP-Fusion 9.03.50. Affected by this issue is the function add_panel_form of the file panels.php of the component POST Parameter Handler. Such manipulation of the argument panel_content leads to improper neutralization of directives in dynamically evaluated code.
This vulnerability is referenced as CVE-2020-37137. It is possible to launch the attack remotely. Furthermore, an exploit is available.