Skip to main content

CVE-2019-7580

8.8
HIGHCVSS v3.1 Base Score
54.98%
MEDIUM RiskEPSS (98th percentile)

ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.

Published: 2/7/2019
Modified: 11/21/2024
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

54.98%MEDIUM Exploitation Risk
98th percentile

This vulnerability has a 54.98% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

Related Vulnerabilities