CRITICAL9.8
GHSA-m7h5-fjjq-559f
SQL Injection in topthink/thinkphp
Details
ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/topthink/thinkphp
Introduced in:
0No fixed version published yet for topthink/thinkphp (composer). Pin to a known-safe version or switch to an alternative.