CVE-2018-20062 is a critical remote code execution (RCE) vulnerability affecting NoneCms V1.3, specifically within the thinkphp/library/think/App.php component. Attackers can leverage a crafted 'filter' parameter in the URL to execute arbitrary PHP code on the server. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating it can be exploited remotely without authentication, with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Its high EPSS score and FAUCET Risk Score of 100/100 underscore its significant threat. CVE-2018-20062 is actively exploited in the wild, with readily available exploit code including Metasploit modules and Nuclei templates. It has garnered substantial community discussion and media coverage, with reports of Chinese threat actors exploiting it to install 'Dama' web shells.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.0CPE matchmatch criteria | cpe:2.3:a:5none:nonecms:1.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.