Skip to content

H3-2025-0049

Thinkphp Remote Code Execution Vulnerability

Category VULNERABILITY
Base Score 9.8

Description

A critical vulnerability in ThinkPHP, a popular PHP framework, allows attackers to execute arbitrary code remotely by manipulating the 's' parameter.

Impact

If exploited, this vulnerability permits attackers to execute arbitrary code on servers using ThinkPHP 5.x, potentially resulting in full server compromise.

References