A local file inclusion (LFI) vulnerability in ThinkPHP versions prior to 6.0.14. Exploited via the lang parameter when language packs are enabled, this flaw allows unauthenticated attackers to execute arbitrary operating system commands. As attackers continue to exploit overlooked vulnerabilities like CVE-2022-47945 while persisting with high-value targets like CVE-2023-49103, it becomes evident that traditional patch management approaches must evolve to incorporate dynamic threat intelligence. Despite its critical nature, this vulnerability is not listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog and has a low Exploit Prediction Scoring System (EPSS) score of 7%. In a significant cybersecurity breach, attackers exploited a critical vulnerability in Palo Alto Networks' PAN-OS firewall software (CVE-2024-0012) to deploy the RA World ransomware. Researchers identified 484 unique IPs targeting this flaw, which has been actively exploited since its disclosure in November 2023 and was listed among the top exploited vulnerabilities of 2023 by CISA, NSA, and FBI. A recent surge in exploitation activity has been observed targeting two critical vulnerabilities, CVE-2022-47945 in ThinkPHP and CVE-2023-49103 in ownCloud. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Notably, ThinkPHP vulnerabilities have previously been exploited by Chinese threat actors in targeted campaigns. Organizations must act swiftly to address these vulnerabilities and reassess their vulnerability management strategies to stay ahead of emerging threats. These attacks highlight the persistent threat posed by unpatched systems and the challenges organizations face in prioritizing vulnerability management. It arises from a dependency on a third-party library exposing sensitive PHP environment details via the phpinfo function, including admin credentials, mail server details, and license keys. Kaaviya is a Security Editor and fellow reporter with Cyber Security News.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 13 Feb 2025 13:30:50 +0000