First published: Sun Mar 20 2022(Updated: )
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ThinkPHP ThinkPHP | =5.0.24 | |
composer/topthink/framework | <=5.0.24 | |
=5.0.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-25481.
The severity of CVE-2022-25481 is high with a score of 7.5.
The affected software of CVE-2022-25481 is ThinkPHP Framework version 5.0.24.
Attackers can exploit CVE-2022-25481 by accessing all system environment parameters from index.php due to the misconfiguration of ThinkPHP Framework.
A fix for CVE-2022-25481 is not currently available, but you can refer to the provided reference for more information.