📦

open_source_background_management_system

Vendor: opensourcebms

Actively Exploited 1 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 0 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 97.42% Exploit Prob.
Latest CVE CVE-2019-9082 Feb 24

Security Vulnerability Index

Page 1 / 1
Critical Target
8.8 CVSS
CVE-2019-9082
Exploit Found

ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.

EPSS: 97.42%