VDB
Sign up
HIGH7.5

GHSA-69wp-xwm7-69wm

Exposure of Resource to Wrong Sphere in ThinkPHP Framework

Details

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/topthink/framework
Introduced in: 0

No fixed version published yet for topthink/framework (composer). Pin to a known-safe version or switch to an alternative.

References