Lucene search

K
cvelistMitreCVELIST:CVE-2019-7580
HistoryOct 03, 2022 - 4:19 p.m.

CVE-2019-7580

2022-10-0316:19:29
mitre
www.cve.org
1
thinkcmf 5.0.190111
remote code execution
alias parameter
data/conf/route.php injection

9.2 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.0%

ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.

9.2 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.0%

Related for CVELIST:CVE-2019-7580