FortiGuard Labs is observing active exploitation of several ThinkPHP remote code execution vulnerabilities (CVE-2019-9082 and CVE-2018-20062). Successful exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the affected system. Both vulnerabilities are on CISA’s Known Exploited Vulnerabilities (KEV) catalog.Why is this Significant?This is significant because active exploitation of CVE-2019-9082 and CVE-2018-20062 is being observed. Also, Proof-of-Concept (PoC) code is publicly available for both vulnerabilities. They are on CISA’s Known Exploited Vulnerabilities (KEV) catalog. As such, patches should be applied as soon as possible.What is CVE-2019-9082?CVE-2019-9082 is a PHP injection vulnerability that affects ThinkPHP prior to version 3.2.4. Successful exploitation could allow a remote attacker to execute arbitrary code on the affected system. The vulnerability has a CVSS base score of 8.8.What is CVE-2018-20062?CVE-2018-20062 is a PHP injection vulnerability that affects ThinkPHP prior to version 5.0.23. Successful exploitation could allow a remote attacker to execute arbitrary code on the affected system. The vulnerability has a CVSS base score of 9.8.Is Patch Available for CVE-2019-9082 and CVE-2018-20062?Yes, patch is available for both CVE-2019-9082 and CVE-2018-20062.What is the Status of Protection?FortiGuard Labs has the following IPS signatures in place for CVE-2019-9082 and CVE-2018-20062:ThinkPHP.Controller.Parameter.Remote.Code.Execution
More Stories
USN-7418-1: Ruby vulnerabilities
It was discovered that Ruby incorrectly handled parsing of an XML document that has specific XML characters in an attribute...
thunderbird-128.9.0-1.fc40
FEDORA-2025-4841d72caf Packages in this update: thunderbird-128.9.0-1.fc40 Update description: Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/ Read More
thunderbird-128.9.0-1.fc41
FEDORA-2025-9a271ccfb3 Packages in this update: thunderbird-128.9.0-1.fc41 Update description: Update to 128.9.0 https://www.thunderbird.net/en-US/thunderbird/128.9.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/ Read More
php-tcpdf-6.9.1-1.fc40
FEDORA-2025-b5809de628 Packages in this update: php-tcpdf-6.9.1-1.fc40 Update description: Version 6.9.1 (2025-04-03) Fixed Path Traversal security vulnerability reported by Positive Technologies....
php-tcpdf-6.9.1-1.fc42
FEDORA-2025-39c7a4c7ce Packages in this update: php-tcpdf-6.9.1-1.fc42 Update description: Version 6.9.1 (2025-04-03) Fixed Path Traversal security vulnerability reported by Positive Technologies....
php-tcpdf-6.9.1-1.fc41
FEDORA-2025-85549e07c8 Packages in this update: php-tcpdf-6.9.1-1.fc41 Update description: Version 6.9.1 (2025-04-03) Fixed Path Traversal security vulnerability reported by Positive Technologies....