Record summary

CVE-2022-47945 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 11, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 15, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 6.0.14 · Fixed in 6.0.14affected

Nuclei templates

1
ProjectDiscoveryCRITICALThinkphp Lang - Local File InclusionCVSS 9.8

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.

Impact

This vulnerability can lead to unauthorized access, data leakage, and remote code execution.

Remediation

Apply the latest security patches and updates provided by the Thinkphp framework.

WeaknessesCWE-22
Authorskagamigawa
Template tagscvecve2022thinkphplfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:thinkphp:thinkphp:*:*:*:*:*:*:*:*
Shodan: title:"Thinkphp"
Shodan: http.title:"thinkphp"
Shodan: cpe:"cpe:2.3:a:thinkphp:thinkphp"
FOFA: header="think_lang"
FOFA: title="thinkphp"
Google: intitle:"thinkphp"

Source: ProjectDiscovery

References

5