CVE-2019-9082 | ThinkPHP up to 3.2.3 code injection (Exploit 157218 / EUVD-2019-18467)
A vulnerability was found in ThinkPHP up to 3.2.3. It has been classified as critical. This issue affects some unknown processing of the file public/?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]. Performing manipulation results in code injection.
This vulnerability is reported as CVE-2019-9082. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.