blog.riskivy.com
https://blog.riskivy.com/thinkcmf-%e6%a1%86%e6%9e%b6%e4%b8%8a%e7%9a%84%e4%bb%bb%e6%84%8f%e5%86%85%e5%ae%b9%e5%8c%85%e5%90%ab%e6%bc%8f%e6%b4%9e CVE-2020-20601
CRITICALNuclei
thinkcmf thinkcmf Improper Control of Generation of Code ('Code Injection')
Record summary
CVE-2020-20601 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 5, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
thinkcmfBrowse thinkcmf / thinkcmf | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALThinkCMF X2.2.2 - Remote Code ExecutionCVSS 9.8
ThinkCMF X2.2.2 and below contain a remote code execution caused by processing crafted packets, letting attackers execute arbitrary code remotely, exploit requires sending malicious packets.
Impact
Unauthenticated attackers can execute arbitrary PHP code on ThinkCMF servers, leading to complete server compromise and access to all website data.
Remediation
Upgrade to ThinkCMF version X2.2.3 or later.
WeaknessesCWE-94
Authorspikpikcu
Template tagscvecve2020thinkcmfrcevulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:thinkcmf:thinkcmf:x2.2.2:*:*:*:*:*:*:*
https://www.shuzhiduo.com/A/l1dygr36Je/ https://blog.riskivy.com/thinkcmf-%e6%a1%86%e6%9e%b6%e4%b8%8a%e7%9a%84%e4%bb%bb%e6%84%8f%e5%86%85%e5%ae%b9%e5%8c%85%e5%90%ab%e6%bc%8f%e6%b4%9e/
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-20601