Thinkcmf RCE

By
Febna V M
Published on
16 Jun 2021

The fetch and display functions in the HomeBaseController class(parent class of IndexController) and AdminbaseController class are assigned as public so that they can be accessed easily from outside. A remote attacker can use this vulnerability to construct a malicious URL and write files of arbitrary content to the server without any permission to achieve the purpose of remote code execution.

Affected versions

ThinkCMF X1.6.0,ThinkCMF X2.1.0,ThinkCMF X2.2.0,ThinkCMF X2.2.1,ThinkCMF X2.2.2ThinkCMF X2.2.3

Mitigation / Precaution

  • We recommend you to change the modifiers of the display and fetch functions in the HomebaseController.class.php and AdminbaseController.class.php classes to protected.
Automated human-like penetration testing for your web apps & APIs
Teams using Beagle Security are set up in minutes, embrace release-based CI/CD security testing and save up to 65% with timely remediation of vulnerabilities. Sign up for a free account to see what it can do for you.

Written by
Febna V M
Febna V M
Cyber Security Engineer
Find website security issues in a flash
Improve your website's security posture with proactive vulnerability detection.
Free website security assessment
Experience the power of automated penetration testing & contextual reporting.