CVE-2019-9082
thinkphp, opensourcebms open source background management system, zzzcms zzzphp
Published 24 Feb 2019 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
References
- packetstormsecurity.com/files/157218/ThinkPHP-5.0.23-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- github.com/xiayulei/open_source_bms/issues/33 · Exploit, Issue Tracking, Third Party Advisory
- www.exploit-db.com/exploits/46488/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-9082 · US Government Resource