CVE-2019-9082

CVE Published 2019-02-24
Related CWE(s) CWE-306: Missing Authentication for Critical Function, CWE-94: Improper Control of Generation of Code ('Code Injection')
Related Vendor(s) opensourcebms, zzzcms, thinkphp
Related Product(s) open_source_background_management_system, thinkphp, zzzphp
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 8.8 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References