thinkcmf Vulnerabilities and Affected Products
Vulnerabilities associated with thinkcmf.
Products
Clear product- thinkcmf3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-31615CRITICAL | ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php. CWE-434Apr 25, 2024 | CVSS9.8v3.1 | EPSS0.712% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-20601CRITICAL | thinkcmf thinkcmf Improper Control of Generation of Code ('Code Injection')An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet. | CVSS9.8v3.1 | EPSS7.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2019-7580HIGH | thinkcmf thinkcmf Improper Control of Generation of Code ('Code Injection')ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection. CWE-94Feb 7, 2019 | CVSS8.8v3.0 | EPSS9.93% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |