CVE-2024-34467: XSS
ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in thinkexception.tpl.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34467?
CVE-2024-34467 has a medium severity rating due to the potential for remote attackers to exploit the XSS vulnerability.
How do I fix CVE-2024-34467?
To fix CVE-2024-34467, upgrade to version 8.0.4 or apply the necessary patches for your version of the topthink/framework package.
Which versions of ThinkPHP are affected by CVE-2024-34467?
CVE-2024-34467 affects ThinkPHP versions prior to 8.0.4, including versions 8.0.0 to 8.0.3 and lower 6.x versions.
Can CVE-2024-34467 lead to data breaches?
Yes, CVE-2024-34467 can lead to data breaches through exploitation of XSS, allowing attackers to execute malicious scripts in users' browsers.
Is any user input affected by CVE-2024-34467?
Yes, the vulnerability stems from inadequate filtering of function argument values, indicating that user input may be exploited.