PT-2025-31940 · Thinkphp3 · Thinkphp3

Xinyisleep

·

Published

2025-08-05

·

Updated

2025-08-05

·

CVE-2025-50707

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions thinkphp3 version 3.2.5
Description An issue in thinkphp3 allows a remote attacker to execute arbitrary code via the index.php component. This can be achieved through crafted template inclusion, requiring no login.
Recommendations Block public access to index.php. Add Web Application Firewall (WAF) rules.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-50707

Affected Products

Thinkphp3