Vulnerability Description
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thinkcmf | Thinkcmf | 5.0.190111 |
Related Weaknesses (CWE)
References
- http://www.ttk7.cn/post-108.htmlPermissions RequiredThird Party Advisory
- https://www.thinkcmf.com/download.htmlRelease NotesVendor Advisory
- http://www.ttk7.cn/post-108.htmlPermissions RequiredThird Party Advisory
- https://www.thinkcmf.com/download.htmlRelease NotesVendor Advisory
FAQ
What is CVE-2019-6713?
CVE-2019-6713 is a vulnerability with a CVSS score of 9.8 (CRITICAL). app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into...
How severe is CVE-2019-6713?
CVE-2019-6713 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-6713?
Check the references section above for vendor advisories and patch information. Affected products include: Thinkcmf Thinkcmf.