CVE-2022-44289: Malicious File Upload
Published Dec 6, 2022
·Updated
Thinkphp 5.1.41 and 5.0.24 has a code logic error which causes file upload getshell.
Affected Software
2 affected components
ThinkPHP ThinkPHP=5.0.24
ThinkPHP ThinkPHP=5.1.41
Event History
Dec 6, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of Thinkphp 5.1.41 and 5.0.24?
The vulnerability ID is CVE-2022-44289.
2
What is the severity rating of CVE-2022-44289?
The severity rating of CVE-2022-44289 is high.
3
What does the vulnerability in Thinkphp 5.1.41 and 5.0.24 allow?
The vulnerability in Thinkphp 5.1.41 and 5.0.24 allows an attacker to upload files and potentially gain remote code execution.
4
How can I fix the code logic error in Thinkphp 5.1.41 and 5.0.24?
To fix the code logic error in Thinkphp 5.1.41 and 5.0.24, apply the official patch or update to a version that addresses the vulnerability.
5
Where can I find more information about the vulnerability?
You can find more information about the vulnerability in Thinkphp 5.1.41 and 5.0.24 on the GitHub issue page: https://github.com/top-think/framework/issues/2772.