First published: Fri May 06 2022(Updated: )
The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
ThinkPHP ThinkPHP | <6.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23592 is a vulnerability in the topthink/framework package before version 6.0.12 that allows for Deserialization of Untrusted Data due to an insecure unserialize method in the Driver class.
CVE-2021-23592 has a severity rating of 9.8, which is considered critical.
To fix CVE-2021-23592, update to version 6.0.12 or later of the topthink/framework package.
Versions of the topthink/framework package up to and excluding 6.0.12 are affected by CVE-2021-23592.
You can find more information about CVE-2021-23592 in the following references: - [GitHub commit](https://github.com/top-think/framework/commit/d3b5aeae94bc71bae97977d05cd12c3e0550905c) - [GitHub release](https://github.com/top-think/framework/releases/tag/v6.0.12) - [Snyk vulnerability report](https://snyk.io/vuln/SNYK-PHP-TOPTHINKFRAMEWORK-2385695)