An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.
Is CVE-2018-20062 exploited?
Listed in the CISA KEV catalog on 2021-11-03.
Federal remediation due 2022-05-03.
Past that date by 1565 days.
EPSS puts exploitation in the next 30 days at 99.5%.
Public exploit code: packaged in a public tool.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2018-20062
PlainSec has not published a story about this CVE.