CVE-2019-12099 describes a critical remote code execution vulnerability in PHP-Fusion 9.03.00, specifically within the avatar upload functionality of edit_profile.php. This flaw, rated 8.8 HIGH (CVSSv3), allows authenticated attackers to upload and execute arbitrary code due to improper handling of executable files. While not observed in active exploitation (KEV: No), a Metasploit module (EDB-46839) exists, indicating readily available exploit code, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.03.00CPE matchmatch criteria | cpe:2.3:a:php-fusion:php-fusion:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.