CVE-2021-44892: High severity thinkphp vulnerability
Published Feb 10, 2022
·Updated
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[filename] in index.php, which could let a malicious user obtain server control privileges.
Affected Software
2 affected components
composer/topthink/framework<=3.2.3
ThinkPHP ThinkPHP=3.2.3
Event History
Feb 10, 2022
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
Description
Feb 11, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is CVE-2021-44892?
CVE-2021-44892 is a Remote Code Execution (RCE) vulnerability in ThinkPHP 3.x.x via value[_filename] in index.php.
2
How does CVE-2021-44892 affect ThinkPHP?
CVE-2021-44892 could allow a malicious user to obtain server control privileges in ThinkPHP 3.x.x.
3
Which version of ThinkPHP is affected by CVE-2021-44892?
ThinkPHP version 3.2.3 is affected by CVE-2021-44892.
4
How severe is CVE-2021-44892?
CVE-2021-44892 has a severity rating of 8.8 (high).
5
Is there a fix available for CVE-2021-44892?
Yes, users of ThinkPHP 3.x.x are advised to update to a patched version to mitigate the vulnerability.