CVE-2020-37186
EUVD-2020-3113311.02.2026, 21:16
Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system commands through a crafted POST request.
Awaiting analysis
This vulnerability is currently awaiting analysis.