First published: Thu Apr 19 2018(Updated: )
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ThinkPHP ThinkPHP | =3.1.3 | |
composer/topthink/framework | =3.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10225 is a vulnerability in thinkphp 3.1.3 that allows SQL Injection via the index.php s parameter.
CVE-2018-10225 has a severity rating of 9.8 (Critical).
thinkphp 3.1.3 is affected by CVE-2018-10225.
To fix CVE-2018-10225, update thinkphp to a version that is not affected, or apply the latest patch provided by the vendor.
You can find more information about CVE-2018-10225 at http://www.blcat.cn/post-39.html.