EXPOSURES › CVE-2018-20062
CVE-2018-20062
HIGH ⌖ ON CISA KEV · EXPLOITEDThinkPHP's noneCms framework suffered a remote code execution flaw via the filter parameter that was actively exploited in the wild.
An unspecified vulnerability in ThinkPHP's noneCms allowed attackers to execute arbitrary code by manipulating the filter parameter. This failure is critical for DIB organizations because it represents an unpatched, actively exploited RCE that could compromise any system running this framework, leading to data breaches or ransomware deployment. Organizations must audit their frameworks for known KEV vulnerabilities and apply patches immediately.
Shame score — The vendor failed to patch a known, actively exploited RCE vulnerability, demonstrating severe negligence and leaving systems vulnerable to attackers in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.
"ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter."