ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command
Published Feb 24, 2019 ·Due May 3, 2022
8.8
HIGHCVSS 3.1
EPSS 97.42%
Description
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
Affected products
No data.
Configuration 2
- 1.1.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Date Added
Nov 3, 2021
Patch Due
May 3, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 97.42% (0.97419) | 99.90th | v5 (v2026.06.15) |
| Jun 15, 2026 | 97.47% (0.97469) | 99.89th | v5 (v2026.06.15) |
| Nov 21, 2025 | 93.87% (0.93867) | 99.86th | v4 (v2025.03.14) |
| Nov 18, 2025 | 92.29% (0.92294) | 99.79th | v4 (v2025.03.14) |
| Mar 17, 2025 | 94.15% (0.94149) | 99.90th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.43% (0.97427) | 99.96th | v3 (v2023.03.01) |
| Nov 25, 2023 | 97.45% (0.97454) | 99.95th | v3 (v2023.03.01) |
| Sep 20, 2023 | 97.47% (0.97471) | 99.94th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.48% (0.97478) | 99.94th | v3 (v2023.03.01) |
| May 8, 2023 | 97.46% (0.97460) | 99.92th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.47% (0.97473) | 99.93th | v3 (v2023.03.01) |
| Mar 6, 2023 | 84.75% (0.84749) | 99.65th | v2 (v2022.01.01) |
| Aug 4, 2022 | 84.75% (0.84749) | 99.63th | v2 (v2022.01.01) |
| Apr 6, 2022 | 17.59% (0.17593) | 95.91th | v2 (v2022.01.01) |
| Apr 1, 2022 | 20.05% (0.20051) | 96.09th | v2 (v2022.01.01) |
| Feb 4, 2022 | 86.72% (0.86717) | 99.67th | v2 (v2022.01.01) |
| Feb 3, 2022 | 38.17% (0.38170) | 98.15th | v1 |
| Sep 1, 2021 | 38.17% (0.38170) | 99.20th | v1 |
| Apr 14, 2021 | 38.17% (0.38170) | 0.00th | v1 |
References (4)
- http://packetstormsecurity.com/files/157218/ThinkPHP-5.0.23-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
- https://github.com/xiayulei/open_source_bms/issues/33 ExploitIssue TrackingThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-9082 government-resourceUS Government Resource
- https://www.exploit-db.com/exploits/46488/ ExploitThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/157218/ThinkPHP-5.0.23-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry | |
| https://github.com/xiayulei/open_source_bms/issues/33 | ExploitIssue TrackingThird Party Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-9082 | government-resourceUS Government Resource | |
| https://www.exploit-db.com/exploits/46488/ | ExploitThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.