VDB
Sign up
CRITICAL9.8

GHSA-p4qr-vq2g-22wp

ThinkPHP Framework vulnerable to remote code execution

Quick fix

GHSA-p4qr-vq2g-22wp — topthink/framework: upgrade to the fixed version with the command below.

composer require topthink/framework:^6.0.14

Details

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (`lang_switch_on=true`). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including `pearcmd.php`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/topthink/framework
Introduced in: 0Fixed in: 6.0.14
Fixcomposer require topthink/framework:^6.0.14

References