CVE-2018-25270
קריטית 9.8
תיאור (מקור, אנגלית)
ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
9.3 (CRITICAL)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-25/9/2026
- CWE
- CWE-639
מוצרים מושפעים
thinkphp: thinkphp
קישורים
- https://www.exploit-db.com/exploits/45978 ExploitThird Party AdvisoryVDB Entry
- https://github.com/top-think/framework/ Product
- https://thinkphp.cn Broken Link
- https://www.vulncheck.com/advisories/thinkphp-remote-code-execution-via-invoke… Third Party Advisory