AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-6713

CRITICAL · CVSS 9.8 EPSS 2.37%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-23 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable.

CVE
CVE-2019-6713
Severity
CRITICAL
CVSS
9.8
EPSS
2.37%

Original NVD Description

app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated by a file_put_contents call.

Related CVEs

Other vulnerabilities affecting the same vendor(s)