VDB
Sign up
CRITICAL9.8

GHSA-pjhx-j53p-c5f5

ThinkPHP deserialization vulnerability

Details

A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/topthink/thinkphp
Introduced in: 6.1.3

No fixed version published yet for topthink/thinkphp (composer). Pin to a known-safe version or switch to an alternative.

References