CVE-2019-9082: ThinkPHP Remote Code Execution Vulnerability
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=calluserfuncarray&vars[0]=system&vars[1][]= followed by the command.
Other sources
ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=calluserfuncarray&vars[0]=system&vars[1][]= followed by the command.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-9082?
CVE-2019-9082 is a remote code execution vulnerability in ThinkPHP before version 3.2.4, which can be exploited to execute remote commands.
What is the severity of CVE-2019-9082?
CVE-2019-9082 has a severity score of 8.8, which is classified as critical.
What software products are affected by CVE-2019-9082?
ThinkPHP before version 3.2.4, Open Source BMS v1.1.1, and ZZZCMS zzzphp 1.6.1 are affected by CVE-2019-9082.
How can CVE-2019-9082 be exploited?
CVE-2019-9082 can be exploited by sending a specially crafted request to the affected software's public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= endpoint.
Are there any known exploits of CVE-2019-9082?
Yes, there are known exploits of CVE-2019-9082 available at the following references: [1] [2] [3].