MEDIUM6.1
GHSA-969f-v7jv-pgj3
ThinkPHP Cross-Site Scripting Vulnerability
Quick fix
GHSA-969f-v7jv-pgj3 — topthink/framework: upgrade to the fixed version with the command below.
composer require topthink/framework:^8.0.4Details
ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/topthink/framework
Introduced in:
8.0.0Fixed in: 8.0.4Fix
composer require topthink/framework:^8.0.4Packagist/topthink/framework
Introduced in:
6.1.0Fixed in: 6.1.5Fix
composer require topthink/framework:^6.1.5Packagist/topthink/framework
Introduced in:
0Fixed in: 6.0.17Fix
composer require topthink/framework:^6.0.17References
- https://nvd.nist.gov/vuln/detail/CVE-2024-34467[ADVISORY]
- https://github.com/top-think/framework/issues/2996[WEB]
- https://github.com/top-think/framework/commit/403358cd3e510e2fdab63f951930bdd093314eee[WEB]
- https://github.com/top-think/framework/commit/57d1950a1844ef8d3098ea290032aeb92e2e32c3[WEB]
- https://github.com/top-think/framework/commit/d3904e51e279c3b72ee206192aeccf9b1cffb534[WEB]
- https://github.com/top-think/framework[PACKAGE]