CVE-2022-47945
9.8
CRITICAL · CVSS 3.1 · EPSS 28.7% (pctl 98)
Patch early
EPSS 28.7% — above the 10% action threshold.
Description
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 28.73% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-12-23 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| thinkphp | thinkphp |
References
- https://github.com/top-think/framework/commit/c4acb8b4001b98a0078eda25840d33e295a7f099
- https://github.com/top-think/framework/compare/v6.0.13...v6.0.14
- https://tttang.com/archive/1865/
- https://github.com/top-think/framework/commit/c4acb8b4001b98a0078eda25840d33e295a7f099
- https://github.com/top-think/framework/compare/v6.0.13...v6.0.14
- https://tttang.com/archive/1865/
→ the Explorer · watch your stack · NVD