← Vulnerability feed

Vulnerability record · CVE-2019-9082 · published 24 February 2019

CVE-2019-9082: ThinkPHP invokefunction parameter allows remote command execution

Thinkphp · Thinkphp

ThinkPHP before 3.2.4, and products built on it such as Open Source BMS v1.1.1, fails to properly restrict the invokefunction route, letting a crafted request invoke call_user_func_array with attacker-controlled arguments. Because the arguments can name system and carry a command, the flaw yields remote command execution on the server. It matters because the affected framework is widely embedded in PHP applications and the record is on CISA's Known Exploited Vulnerabilities catalog.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 97% · top 0.1% CWE-94 · Code injectionCWE-306 · Missing authentication for critical function
8.8CVSS 3.1 base score, v2 9.3
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
6References, 5 tagged exploit
17 Jun 2026Last modified by NVD

Description

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw gives unauthenticated network-reachable command execution, is listed in CISA KEV, and has an EPSS probability above 0.97.

What it is

ThinkPHP before 3.2.4, and products built on it such as Open Source BMS v1.1.1, fails to properly restrict the invokefunction route, letting a crafted request invoke call_user_func_array with attacker-controlled arguments. Because the arguments can name system and carry a command, the flaw yields remote command execution on the server. It matters because the affected framework is widely embedded in PHP applications and the record is on CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker can run arbitrary operating system commands with the privileges of the web server process, leading to full compromise of the application and its data. Depending on server configuration, this can extend to the underlying host.

Attack surface

The flaw is reached over the network through an HTTP request to the public invokefunction route, as shown in the description's public//?s=index/\think\app/invokefunction path. The CVSS vector marks PR:N but UI:R, so no authentication is required while some form of user interaction is indicated; the record does not explain what that interaction is.

Exploitation

CVE-2019-9082 is listed in CISA KEV with a 2021-11-03 addition date, and multiple references carry the Exploit tag including Packet Storm and Exploit-DB entries. EPSS gives a 30-day probability of 0.97419 (99.896th percentile), indicating very high predicted exploitation activity.

What to do

  • Upgrade ThinkPHP to 3.2.4 or later, and update Open Source BMS and any other bundled product to a release that ships the fixed framework.
  • If immediate upgrade is not possible, block or restrict external access to the invokefunction route and other dynamic call paths at the web server or WAF.
  • Run the PHP application under a low-privilege account with open_basedir and disabled dangerous functions such as system where feasible.
  • Review the CISA KEV required action and apply vendor updates per those instructions within the stated due date.
  • Inventory internet-facing PHP applications for ThinkPHP and related products to find remaining exposed instances.

Detection

  • Search web logs for requests containing invokefunction, call_user_func_array, or vars[0]=system in query strings or POST bodies.
  • Alert on outbound or child processes spawned by the PHP/web server user, especially shell interpreters and common command binaries.
  • Monitor for unexpected file writes or new web shells in application directories following suspicious invokefunction requests.
  • Correlate requests to the affected route with subsequent authentication failures, scanning, or lateral movement from the same source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-9082 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "ThinkPHP Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-9082 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-63888Thinkphp php remote file inclusion vulnerabilityThe read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.EPSS 0.57%9.8CVE-2025-50707Thinkphp code injection vulnerabilityAn issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php componentEPSS 1.0%9.8CVE-2025-50706Thinkphp code injection vulnerabilityAn issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck functionEPSS 1.0%9.8CVE-2024-48112Thinkphp deserialization of untrusted data vulnerabilityA deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.EPSS 0.89%9.8CVE-2024-44902Thinkphp deserialization of untrusted data vulnerabilityA deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.EPSS 4.2%9.8CVE-2022-45982Thinkphp deserialization of untrusted data vulnerabilitythinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a c…EPSS 1.2%9.8CVE-2022-47945Thinkphp path traversal vulnerabilityThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). …EPSS 28%9.8CVE-2022-38352Thinkphp deserialization of untrusted data vulnerabilityThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerab…EPSS 21%

Source: NIST National Vulnerability Database (record CVE-2019-9082), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.