Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2019-9082

CRITICAL · 9.5 CVSS Gepubliceerd: CWE-306

Beschrijving

ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/thinkapp/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

Required action: Apply updates per vendor instructions.

Vendors

Thinkphp

Affected products

Thinkphp

References