xyl-tools/open_source_bms

xyl-tools/open_source_bms

Releases5
Frequency2 months 3 days
Last Release
Stars365
Open Source BMS 后台管理系统

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH9.3 HIGH

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.