← back
CVE-2018-25270criticalobserved exploitationCWE-639

ThinkPHP 5.0.23 Remote Code Execution via invokefunction

70Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.3epss 0.9%
from disclosure to weapon
Published on NVDApr 22
VulnCheck+43d
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Thinkphp · ThinkPHP
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.