add_panel_form of the file panels.php of the component POST Parameter Handler. Such manipulation of the argument panel_content leads to improper neutralization of directives in dynamically evaluated code.This vulnerability is referenced as CVE-2020-37137. It is possible to launch the attack remotely. Furthermore, an exploit is available.