Junglewise Threat Intelligence

CVE-2018-20062: ThinkPHP "noneCms" Remote Code Execution Vulnerability

CVE-2018-20062 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Executive brief

NoneCms V1.3, which utilizes ThinkPHP, contains a remote code execution vulnerability in thinkphp/library/think/App.php. Attackers can execute arbitrary PHP code by supplying a crafted filter parameter in a query string.

Affected products

  • 5none noneCms 1.3.0
  • ThinkPHP ThinkPHP 5.0.23

Timeline

  • 2018-12-11: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV entry