Skip to content
COOEY

EXPOSURES › CVE-2018-20062

CVE-2018-20062

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-20062 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

ThinkPHP's noneCms framework suffered a remote code execution flaw via the filter parameter that was actively exploited in the wild.

An unspecified vulnerability in ThinkPHP's noneCms allowed attackers to execute arbitrary code by manipulating the filter parameter. This failure is critical for DIB organizations because it represents an unpatched, actively exploited RCE that could compromise any system running this framework, leading to data breaches or ransomware deployment. Organizations must audit their frameworks for known KEV vulnerabilities and apply patches immediately.

Shame score — The vendor failed to patch a known, actively exploited RCE vulnerability, demonstrating severe negligence and leaving systems vulnerable to attackers in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
ThinkPHP's CVE-2018-20062 RCE vulnerability in noneCms was widely recognized as a critical flaw allowing remote code execution via filter parameter abuse, resulting in severe fallout for the vendor an
cooey ↗ severe-fallout -0.80
NVD confirms the RCE vulnerability in ThinkPHP noneCms, indicating a severe security failure.
"ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter."
github.com ↗ severe-fallout +0.00
GitHub advisory database entry is unrelated to CVE-2018-20062 and ThinkPHP.
www.cvefind.com ↗ severe-fallout +0.00
CVEFind is a vulnerability database and does not comment on ThinkPHP's CVE-2018-20062.
NVD ↗ severe-fallout +0.00
NVD page for CVE-2026-77647 is unrelated to CVE-2018-20062 and ThinkPHP.
app.opencve.io ↗ severe-fallout +0.00
OpenCVE database entry is unrelated to CVE-2018-20062 and ThinkPHP.
cvefeed.io ↗ severe-fallout +0.00
CVEFeed.io mirrors CISA KEV but does not comment on CVE-2018-20062.
www.youtube.com ↗ severe-fallout +0.00
YouTube video is unrelated to CVE-2018-20062 and ThinkPHP.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.