VDB
Sign up
CRITICAL9.8

GHSA-4vp2-mj4m-69m4

ThinkAdmin insecure unserialize vulnerability

Quick fix

GHSA-4vp2-mj4m-69m4 — zoujingli/thinkadmin: upgrade to the fixed version with the command below.

composer require zoujingli/thinkadmin:^6.1.0

Details

An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in `app/admin/controller/api/Update.php `and `app/wechat/controller/api/Push.php`, which may lead to arbitrary remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/zoujingli/thinkadmin
Introduced in: 4.0Fixed in: 6.1.0
Fixcomposer require zoujingli/thinkadmin:^6.1.0

References