VDB
Sign up
MEDIUM6.1

GHSA-969f-v7jv-pgj3

ThinkPHP Cross-Site Scripting Vulnerability

Quick fix

GHSA-969f-v7jv-pgj3 — topthink/framework: upgrade to the fixed version with the command below.

composer require topthink/framework:^8.0.4

Details

ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/topthink/framework
Introduced in: 8.0.0Fixed in: 8.0.4
Fixcomposer require topthink/framework:^8.0.4
Packagist/topthink/framework
Introduced in: 6.1.0Fixed in: 6.1.5
Fixcomposer require topthink/framework:^6.1.5
Packagist/topthink/framework
Introduced in: 0Fixed in: 6.0.17
Fixcomposer require topthink/framework:^6.0.17

References