CVE-2018-20062Active Exploitation(5none / nonecms)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch 5none nonecms systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nonecms

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-09-11)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
nonecms

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-08: 1Mentions · 2026-09-11: 2PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-09-11: 1Active Exploitation · 2026-04-08: 1Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 104-0809-11
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
PoC
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-081
Active Exploitation1
2026-09-112
Disclosure1PoC1
Full discourse3 posts
  • Root Rat@root_rat
    Active Exploitation

    🔀 Investigar la IP 185.250.37.153 (Contabo GmbH, Francia) bloqueada por CrowdSec en s1. Quiero un informe completo: quién es, qué ASN, reputación, historial de abuso, geolocalización precisa, puertos escaneados, vectores de ataque (ThinkPHP CVE-2018-20062, PHPUnit CVE-2017-9841, HTTP probing), y si es un actor conocido o probable bot. ⚡ Investigar IP 185.250.37.153 - reputación, historial de abuso, geolocalización, ASN Contabo, amenazas conocidas, ThinkPHP CVE-2018-20062, PHPUnit CVE-2017-9841 💻 ssh s1 "cd /opt/rattalks && echo '=== CROWDSEC ALERTS DETAIL ===' && docker compose exec -T crowdsec cscli alerts list --limit 50 2>&1 | grep '185.250.37.153' && echo && echo '=== TRAEFIK LOGS from this IP ===' && docker compose logs --since 24h traefik 2>&1 | grep '185.250.37.153' | tail -30 && echo && echo '=== BACKEND LOGS from this IP ===' && docker compose logs --since 24h backend 2>&1 | grep '185.250.37.153' | tail -20" 🔍 Investigación: IP 185.250.37.153 (Contabo GmbH) 📋 Datos generales CampoValorIP185.250.37.153ASNAS51167 — Contabo GmbHPaís registro🇫🇷 FR (datacenter Contabo, probablemente Núremberg/Múnich DE)TipoVPS / Dedicated hosting de bajo costoReputación⚠️ Alta probabilidad en listas negras 🕵️ Patrón de ataque detectado Esta IP ya atacó ayer y volvió hoy — misma secuencia las dos veces: Timestamp (UTC)Alertas CrowdSec2026-04-07 12:52:03http-probing + CVE-2017-9841 + thinkphp-cve-2018-200622026-04-08 07:51:28http-probing + CVE-2017-9841 + thinkphp-cve-2018-20062 3 escenarios en cada visita, siempre en el mismo orden: HTTP Probing — reconoce la superficie del servidor PHPUnit CVE-2017-9841 — intenta explotar /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php (RCE, CVSS 9.8) ThinkPHP CVE-2018-20062 — intenta RCE vía parámetro filter en thinkphp/library/think/App.php Es un escaneo automatizado (bot/herramienta de pentest masivo). El patrón secuencial es típico de tools como nuclei, nikto o frameworks similares que lanzan payloads de CVEs conocidos en cadena. 🎯 ¿Nos afecta? No. RatTalks no usa ni ThinkPHP ni PHPUnit expuesto, así que los payloads no habrían ejecutado nada. Además: ✅ CrowdSec baneó la IP en ambas ocasiones antes de que pudiera seguir ✅ Los logs de Traefik no muestran tráfico de esta IP llegando al backend → el ban funciona correctamente ✅ Los logs del backend no registran nada de esta IP → nunca pasó el proxy 🏢 Sobre Contabo Contabo es un proveedor alemán de VPS baratos. Es notoriamente popular entre actores de amenazas porque: Precios muy bajos → easy spin-up de instancias de ataque Registro con mínima verificación Amplio historial de abuso reportado ✅ Acciones recomendadas Mantener el ban de CrowdSec — ya en vigor, expira en ~20h. Opcionalmente se puede hacer permanente No es necesario un ban permanente — es bot genérico, no un actor dirigido contra nosotros Todo OK — la infraestructura está parcheada y el stack de seguridad funciona como debe ¿Quieres que convierta el ban en permanente, o lo dejamos con las reglas automáticas de CrowdSec?

    Post summary

    The post details an investigation of an IP that actively attempted to exploit ThinkPHP and PHPUnit CVEs, confirms the attempts were blocked, and notes that the infrastructure is appropriately patched.

    41029104.0K
    17.3K followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] CVE-2018-20062 [CRITICAL/PoC] CVE-2018-20062 🔗 https://exploitgrid.net/exploits/c55c4f5a-dc1d-4b8d-a208-bed593e10e24

    Post summary

    A critical Proof of Concept for CVE‑2018‑20062 is linked via ExploitGrid, but no evidence of active exploitation or suggested patches is provided.

    1000045
    42 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2018-20062 CVE-2023-25157 CVE-2024-4577 CVE-2026-20253 CVE-2026-41096 ..🧵👇

    Post summary

    The tweet announces a list of five critical exploits disclosed today, but provides no further details, PoC links, or evidence of active exploitation.

    1000078
    42 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
App5nonenonecms1.3.0--

Explore more