C
hevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system commands through a crafted POST request.
References
Configurations
No configuration.
History
12 Feb 2026, 15:10
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-11 21:16
Updated : 2026-02-12 15:10
NVD link : CVE-2020-37186
Mitre link : CVE-2020-37186
CVE.ORG link : CVE-2020-37186
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')