CVE-2021-44350: SQL Injection
Published Dec 15, 2021
·Updated
SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.
Affected Software
2 affected components
composer/topthink/framework>=5.0<=5.1.22
ThinkPHP ThinkPHP>=5.0.0<=5.1.22
Event History
Dec 15, 2021
CVE Published
via MITRE·10:09 PM
Data Sourced
via MITRE·10:09 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Dec 17, 2021
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is CVE-2021-44350?
CVE-2021-44350 is a SQL Injection vulnerability that exists in ThinkPHP5 5.0.x <=5.1.22 through the parseOrder function in Builder.php.
2
How severe is CVE-2021-44350?
CVE-2021-44350 has a severity rating of 9.8, which is considered critical.
3
What software versions are affected by CVE-2021-44350?
ThinkPHP 5.0.x <=5.1.22 is affected by CVE-2021-44350.
4
How can I fix CVE-2021-44350?
To fix CVE-2021-44350, update your ThinkPHP installation to a version later than 5.1.22.
5
Where can I find more information about CVE-2021-44350?
More information about CVE-2021-44350 can be found at https://github.com/top-think/framework/issues/2613.