vendor:
ThinkPHP
by:
vr_system
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: ThinkPHP
Affected Version From: 5.0.22
Affected Version To: 5.1.29
Patch Exists: YES
Related CWE: None
CPE: a:thinkphp:thinkphp:5.x
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7/10
2019
thinkphp 5.X RCE
ThinkPHP is an open source PHP framework. A remote code execution vulnerability exists in ThinkPHP 5.X versions due to improper input validation. An attacker can exploit this vulnerability by sending a crafted payload to the vulnerable application. This can allow the attacker to execute arbitrary code on the vulnerable system.
Mitigation:
Upgrade to the latest version of ThinkPHP 5.X and apply the latest security patches.