CVE-2022-47945 is a critical local file inclusion vulnerability affecting ThinkPHP Framework versions before 6.0.14, specifically when the language pack feature is enabled. This flaw allows an unauthenticated, remote attacker to execute arbitrary operating system commands, as demonstrated by including pearcmd.php. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk, enabling complete compromise of confidentiality, integrity, and availability. While no Metasploit or ExploitDB modules exist, Nuclei templates are available, and there is significant community discussion and media coverage, including reports of active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.0.14CPE matchmatch criteria | cpe:2.3:a:thinkphp:thinkphp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.