CVE-2018-20062: ThinkPHP "noneCms" Remote Code Execution Vulnerability
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.
Other sources
ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20062?
The severity of CVE-2018-20062 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2018-20062?
The affected software for CVE-2018-20062 is ThinkPHP noneCms version 1.3.0.
How does CVE-2018-20062 allow remote code execution?
CVE-2018-20062 allows remote attackers to execute arbitrary PHP code through crafted use of the filter parameter in thinkphp/library/think/App.php.
Is there a known fix for CVE-2018-20062?
At this time, there is no known fix for CVE-2018-20062. It is recommended to upgrade to a patched version or apply any available security patches.
Are there any references available for CVE-2018-20062?
Yes, you can find more information on CVE-2018-20062 at the following references: [Link 1](http://packetstormsecurity.com/files/157218/ThinkPHP-5.0.23-Remote-Code-Execution.html) and [Link 2](https://github.com/nangge/noneCms/issues/21).