RULE(RULE ID:330917)

Rule General Information
Release Date: 2024-04-29
Rule Name: ThinkCMF Alias Parameter Arbitrary Code Execution Vulnerability (CVE-2019-7580)
Severity:
CVE ID:
Rule Protection Details
Description: ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.
Impact: An attacker could exploit this vulnerability to execute arbitrary php code.
Affected OS: Windows, Others
Reference: https://github.com/shadowsock5/ThinkCMF-5.0.190111/blob/master/README.md
https://xz.aliyun.com/t/3997
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.thinkcmf.com/