Vulnerability record · CVE-2019-9082 · published 24 February 2019
CVE-2019-9082: ThinkPHP invokefunction parameter allows remote command execution
Thinkphp · Thinkphp
ThinkPHP before 3.2.4, and products built on it such as Open Source BMS v1.1.1, fails to properly restrict the invokefunction route, letting a crafted request invoke call_user_func_array with attacker-controlled arguments. Because the arguments can name system and carry a command, the flaw yields remote command execution on the server. It matters because the affected framework is widely embedded in PHP applications and the record is on CISA's Known Exploited Vulnerabilities catalog.
Description
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw gives unauthenticated network-reachable command execution, is listed in CISA KEV, and has an EPSS probability above 0.97.
What it is
ThinkPHP before 3.2.4, and products built on it such as Open Source BMS v1.1.1, fails to properly restrict the invokefunction route, letting a crafted request invoke call_user_func_array with attacker-controlled arguments. Because the arguments can name system and carry a command, the flaw yields remote command execution on the server. It matters because the affected framework is widely embedded in PHP applications and the record is on CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker can run arbitrary operating system commands with the privileges of the web server process, leading to full compromise of the application and its data. Depending on server configuration, this can extend to the underlying host.
Attack surface
The flaw is reached over the network through an HTTP request to the public invokefunction route, as shown in the description's public//?s=index/\think\app/invokefunction path. The CVSS vector marks PR:N but UI:R, so no authentication is required while some form of user interaction is indicated; the record does not explain what that interaction is.
Exploitation
CVE-2019-9082 is listed in CISA KEV with a 2021-11-03 addition date, and multiple references carry the Exploit tag including Packet Storm and Exploit-DB entries. EPSS gives a 30-day probability of 0.97419 (99.896th percentile), indicating very high predicted exploitation activity.
What to do
- Upgrade ThinkPHP to 3.2.4 or later, and update Open Source BMS and any other bundled product to a release that ships the fixed framework.
- If immediate upgrade is not possible, block or restrict external access to the invokefunction route and other dynamic call paths at the web server or WAF.
- Run the PHP application under a low-privilege account with open_basedir and disabled dangerous functions such as system where feasible.
- Review the CISA KEV required action and apply vendor updates per those instructions within the stated due date.
- Inventory internet-facing PHP applications for ThinkPHP and related products to find remaining exposed instances.
Detection
- Search web logs for requests containing invokefunction, call_user_func_array, or vars[0]=system in query strings or POST bodies.
- Alert on outbound or child processes spawned by the PHP/web server user, especially shell interpreters and common command binaries.
- Monitor for unexpected file writes or new web shells in application directories following suspicious invokefunction requests.
- Correlate requests to the affected route with subsequent authentication failures, scanning, or lateral movement from the same source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-9082 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "ThinkPHP Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157218/ThinkPHP-5.0.23-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/xiayulei/open_source_bms/issues/33 | ExploitIssue TrackingThird Party Advisory |
| http://packetstormsecurity.com/files/157218/ThinkPHP-5.0.23-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/xiayulei/open_source_bms/issues/33 | ExploitIssue TrackingThird Party Advisory |
| https://www.exploit-db.com/exploits/46488/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-9082 | US Government Resource |
Track CVE-2019-9082 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-9082), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.