Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13324
HistoryFeb 08, 2019 - 6:45 a.m.

Remote Code Execution (RCE)

2019-02-0806:45:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.003 Low

EPSS

Percentile

68.0%

thinkcmf/thinkcmf is vulnerable to remote code execution. A lack of validation and mishandling of the alias parameter from portal/admin_category/addpost.html allows a remote attacker to execute arbitrary PHP code and OS commands.

CPENameOperatorVersion
thinkcmf/thinkcmfle6.0.0

0.003 Low

EPSS

Percentile

68.0%

Related for VERACODE:13324