First published: Thu Feb 10 2022(Updated: )
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ThinkPHP ThinkPHP | =3.2.3 | |
composer/topthink/framework | <=3.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44892 is a Remote Code Execution (RCE) vulnerability in ThinkPHP 3.x.x via value[_filename] in index.php.
CVE-2021-44892 could allow a malicious user to obtain server control privileges in ThinkPHP 3.x.x.
ThinkPHP version 3.2.3 is affected by CVE-2021-44892.
CVE-2021-44892 has a severity rating of 8.8 (high).
Yes, users of ThinkPHP 3.x.x are advised to update to a patched version to mitigate the vulnerability.