CVE-2022-38352: Critical severity thinkphp vulnerability
Published Sep 15, 2022
·Updated
ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
Affected Software
1 affected component
ThinkPHP ThinkPHP=6.0.13
Event History
Sep 15, 2022
CVE Published
via MITRE·01:05 AM
Data Sourced
via MITRE·01:05 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for ThinkPHP v6.0.13?
The vulnerability ID for ThinkPHP v6.0.13 is CVE-2022-38352.
2
What is the severity level of CVE-2022-38352?
The severity level of CVE-2022-38352 is critical.
3
How can an attacker exploit CVE-2022-38352?
An attacker can exploit CVE-2022-38352 by executing arbitrary code via a crafted payload.
4
Which component does CVE-2022-38352 exploit?
CVE-2022-38352 exploits the component League\Flysystem\Cached\Storage\Psr6Cache.
5
Is there a fix available for CVE-2022-38352?
Yes, a fix for CVE-2022-38352 is available. Please refer to the provided reference link for more information.