HIGH7.5
GHSA-69wp-xwm7-69wm
Exposure of Resource to Wrong Sphere in ThinkPHP Framework
Details
ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/topthink/framework
Introduced in:
0No fixed version published yet for topthink/framework (composer). Pin to a known-safe version or switch to an alternative.