CRITICAL9.8
GHSA-p4qr-vq2g-22wp
ThinkPHP Framework vulnerable to remote code execution
Quick fix
GHSA-p4qr-vq2g-22wp — topthink/framework: upgrade to the fixed version with the command below.
composer require topthink/framework:^6.0.14Details
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (`lang_switch_on=true`). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including `pearcmd.php`.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/topthink/framework
Introduced in:
0Fixed in: 6.0.14Fix
composer require topthink/framework:^6.0.14References
- https://nvd.nist.gov/vuln/detail/CVE-2022-47945[ADVISORY]
- https://github.com/top-think/framework/commit/c4acb8b4001b98a0078eda25840d33e295a7f099[WEB]
- https://github.com/top-think/framework[PACKAGE]
- https://github.com/top-think/framework/compare/v6.0.13...v6.0.14[WEB]
- https://tttang.com/archive/1865[WEB]