VDB
Sign up
CRITICAL9.8

GHSA-m7h5-fjjq-559f

SQL Injection in topthink/thinkphp

Details

ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/topthink/thinkphp
Introduced in: 0

No fixed version published yet for topthink/thinkphp (composer). Pin to a known-safe version or switch to an alternative.

References