First published: Mon Sep 09 2024(Updated: )
A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/topthink/framework | >=6.1.3<=8.0.4 | |
ThinkPHP ThinkPHP | >=6.1.3<=8.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44902 has been classified as a high severity vulnerability due to its potential for arbitrary code execution.
To fix CVE-2024-44902, upgrade ThinkPHP to version 8.0.5 or later.
CVE-2024-44902 affects ThinkPHP versions from 6.1.3 to 8.0.4.
CVE-2024-44902 is a deserialization vulnerability that allows attackers to execute arbitrary code.
Yes, CVE-2024-44902 can be exploited easily if the affected versions of ThinkPHP are not updated.