BRIEFING NOTE: CVE-2018-25270 ThinkPHP 5.0.23 is affected by a critical remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through the routing parameter mechanism. By crafting malicious requests to the index.php endpoint with specially crafted function parameters, attackers can invoke arbitrary functions and execute system commands with full application privileges. The vulnerability carries a CVSS 3.1 score of 9.8 CRITICAL with network-based attack vector, low attack complexity, and no authentication or user interaction required. The impact is severe across all security dimensions, granting attackers high-level confidentiality, integrity, and availability compromise capabilities. With a FAUCET Risk Score of 55.0 out of 100, this represents a significant organizational risk. While the vulnerability is not currently tracked in CISA's Known Exploited Vulnerabilities catalog, it remains actively listed on public vulnerability databases and maintains community attention. The attack surface and public knowledge of this vulnerability suggest continued risk of exploitation, warranting immediate patching of affected ThinkPHP installations to versions beyond 5.0.23.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.0.23CPE matchmatch criteria | cpe:2.3:a:thinkphp:thinkphp:*:*:*:*:*:*:*:* | ||
5.1.31CPE matchmatch criteria | cpe:2.3:a:thinkphp:thinkphp:5.1.31:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.