Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system commands through a crafted POST request.

Project Subscriptions

Vendors Products
Chevereto Subscribe
Chevereto Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 12 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Chevereto
Chevereto chevereto
Vendors & Products Chevereto
Chevereto chevereto

Wed, 11 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
Description Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system commands through a crafted POST request.
Title Chevereto 3.13.4 Core - Remote Code Execution
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-12T16:34:10.535Z

Reserved: 2026-02-10T18:41:38.681Z

Link: CVE-2020-37186

cve-icon Vulnrichment

Updated: 2026-02-12T16:34:06.624Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-11T21:16:12.420

Modified: 2026-02-12T15:10:37.307

Link: CVE-2020-37186

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-12T10:00:59Z

Weaknesses