PT-2026-7684 · Chevere Spa · Chevereto

Jinny Ramsmark

·

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2020-37186

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chevereto version 3.13.4
Description Remote code execution is possible during the database configuration installation. Attackers can manipulate the database table prefix parameter table prefix to write a PHP shell file and execute arbitrary system commands via a crafted POST request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2020-37186

Affected Products

Chevereto