PT-2026-7684 · Chevere Spa · Chevereto

·

CVE-2020-37186

·

Published

2026-02-11

·

Updated

2026-02-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chevereto version 3.13.4
Description Remote code execution is possible during the database configuration installation. Attackers can manipulate the database table prefix parameter table prefix to write a PHP shell file and execute arbitrary system commands via a crafted POST request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-37186

Affected Products

Chevereto