CVE-2019-7580

    Dashboard / Vulnerabilities / CVE-2019-7580

    CVE-2019-7580

    Published: 7 Feb 2019Last Modified: 8 Jul 2026

    Summary:

    Details: ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- c02d1e31b2c353de8fab8dc8fdb1d4fb2097ccd0
    Fixed -None

    Affected versions

    5.0.190111

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High