VDB
Sign up
CRITICAL9.8

GHSA-3fpv-54ff-wqfj

Deserialization of Untrusted Data in topthink/framework

Quick fix

GHSA-3fpv-54ff-wqfj — topthink/framework: upgrade to the fixed version with the command below.

composer require topthink/framework:^6.0.12

Details

The package topthink/framework before version 6.0.12 is vulnerable to Deserialization of Untrusted Data due to insecure `unserialize` method in the `Driver` class.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/topthink/framework
Introduced in: 0Fixed in: 6.0.12
Fixcomposer require topthink/framework:^6.0.12

References