CVE-2018-10225: SQL Injection
Published Apr 19, 2018
·Updated
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.
Affected Software
2 affected components
composer/topthink/framework=3.1.3
ThinkPHP ThinkPHP=3.1.3
Event History
Apr 19, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
May 14, 2022
Advisory Published
via GitHub·03:22 AM
Frequently Asked Questions
1
What is CVE-2018-10225?
CVE-2018-10225 is a vulnerability in thinkphp 3.1.3 that allows SQL Injection via the index.php s parameter.
2
How severe is CVE-2018-10225?
CVE-2018-10225 has a severity rating of 9.8 (Critical).
3
What software is affected by CVE-2018-10225?
thinkphp 3.1.3 is affected by CVE-2018-10225.
4
How can I fix CVE-2018-10225?
To fix CVE-2018-10225, update thinkphp to a version that is not affected, or apply the latest patch provided by the vendor.
5
Where can I find more information about CVE-2018-10225?
You can find more information about CVE-2018-10225 at http://www.blcat.cn/post-39.html.