CVE-2022-45982: Critical severity thinkphp vulnerability
Published Feb 8, 2023
·Updated
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
Affected Software
2 affected components
ThinkPHP ThinkPHP>=6.0.0<=6.0.13
ThinkPHP ThinkPHP=6.1.0
Event History
Feb 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-45982.
2
What is the severity of CVE-2022-45982?
The severity of CVE-2022-45982 is critical.
3
Which versions of thinkphp are affected by CVE-2022-45982?
thinkphp versions 6.0.0 to 6.0.13 and 6.1.0 to 6.1.1 are affected by CVE-2022-45982.
4
How does the deserialization vulnerability in thinkphp allow attackers to execute arbitrary code?
The deserialization vulnerability in thinkphp allows attackers to execute arbitrary code by sending a crafted payload.
5
Is there a fix available for CVE-2022-45982?
Yes, upgrading to a fixed version of thinkphp will fix the vulnerability.