CVE-2022-33107: Critical severity thinkphp vulnerability
Published Jun 29, 2022
·Updated
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
Affected Software
1 affected component
ThinkPHP ThinkPHP=6.0.12
Event History
Jun 29, 2022
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-33107.
2
What is the severity of CVE-2022-33107?
CVE-2022-33107 has a severity level of critical.
3
What is the affected software for CVE-2022-33107?
The affected software for CVE-2022-33107 is ThinkPHP v6.0.12.
4
How can an attacker exploit CVE-2022-33107?
Attackers can exploit CVE-2022-33107 by using a crafted payload to execute arbitrary code.
5
Is there a fix available for CVE-2022-33107?
Yes, a fix is available for CVE-2022-33107. It is recommended to update to a patched version of ThinkPHP.