Junglewise Threat Intelligence

CVE-2019-9082: ThinkPHP Remote Code Execution Vulnerability

CVE-2019-9082 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Executive brief

ThinkPHP before version 3.2.4 contains a remote code execution vulnerability due to improper handling of the invokefunction method. An attacker can execute arbitrary system commands by sending a specially crafted request using the call_user_func_array function via the s parameter.

Affected products

  • ThinkPHP ThinkPHP before 3.2.4
  • Open Source BMS Open Source BMS 1.1.1

Timeline

  • 2019-02-24: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported exploited in the wild per CISA KEV catalog entry date.