CVE-2019-9082
Known Exploited (CISA KEV)HIGH
8.8
CVSS Severity Score
Vulnerability Description
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
Affected Platforms (CPE)
π¦
Thinkphp
Thinkphp
< 3.2.4π¦
Opensourcebms
Open Source Background Management System
= 1.1.1π¦
Zzzcms
