CyberSec.Space Logo
Back to CVE Browser

CVE-2019-9082

Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
EPSS Score60.3220%
EPSS Percentile86.32th
PublishedFeb 24, 2019
Last ModifiedDec 9, 2025

Vulnerability Description

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

Affected Platforms (CPE)

πŸ“¦
Thinkphp

Thinkphp

< 3.2.4
πŸ“¦
Opensourcebms

Open Source Background Management System

= 1.1.1
πŸ“¦
Zzzcms

Zzzphp

= 1.6.1

References & Advisories

Related Vulnerabilities