Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2019-6713 Details

Description

app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://www.thinkcmf.com/download.html CVERelease NotesVendor Advisory
http://www.ttk7.cn/post-108.html CVEPermissions RequiredThird Party Advisory
https://www.thinkcmf.com/download.html [email protected]Release NotesVendor Advisory
http://www.ttk7.cn/post-108.html [email protected]Permissions RequiredThird Party Advisory

Weakness Enumeration

CWE-IDCWE NameSource
CWE-94Improper Control of Generation of Code ('Code Injection')[email protected]

Affected Products

ProductVersions
thinkcmf thinkcmf
5.0.190111

CPE

  • cpe:2.3:a:thinkcmf:thinkcmf:5.0.190111:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2019-6713
NVD Published Date:
Jan 23, 2019
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2019-6713 Details - Not Deferred