logo

Surge in attacks exploiting old ThinkPHP and ownCloud flaws

ID: d9e7e368-ee34-5227-b10d-3b21d8013236

STIX ID: report--d9e7e368-ee34-5227-b10d-3b21d8013236

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-02-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GreyNoise and other sources report a recent surge in automated exploitation targeting two older, critical vulnerabilities — ThinkPHP CVE-2022-47945 (LFI/RCE in affected language-pack-enabled deployments) and ownCloud CVE-2023-49103 (exposes PHP environment leading to credential/data theft). Hundreds of unique IPs have been observed probing and exploiting unpatched instances; operators are advised to upgrade ThinkPHP to 6.0.14+ and ownCloud GraphAPI to 0.3.1+, or take exposed instances offline/behind a firewall.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.