First published: Mon Sep 03 2018(Updated: )
ThinkPHP before 5.1.23 allows SQL Injection via the `public/index/index/test/index` query string.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ThinkPHP ThinkPHP | <5.1.23 | |
composer/topthink/framework | <5.1.23 | 5.1.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for ThinkPHP before 5.1.23 is CVE-2018-16385.
The severity of CVE-2018-16385 is critical, with a score of 9.8.
ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.
ThinkPHP versions up to 5.1.23 are affected by CVE-2018-16385.
More information about CVE-2018-16385 can be found at the following references: [Vulnerability Details](https://exchange.xforce.ibmcloud.com/vulnerabilities/149288), [GitHub Issue](https://github.com/top-think/framework/issues/1375).