Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-7580

ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.581
EPSS Ranking 98.1%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2019-7580
  • Thinkcmf » Thinkcmf » Version: 5.0.190111
    cpe:2.3:a:thinkcmf:thinkcmf:5.0.190111


Contact Us

Shodan ® - All rights reserved