PT-2026-34466 · Undefined · Undefined

Published

2026-04-22

·

Updated

2026-04-22

·

CVE-2018-25270

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2018-25270

Affected Products

Undefined