CRITICAL9.8
GHSA-q868-c4vw-qjx3
ThinkPHP5 SQL Injection vulnerability
Details
SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/topthink/framework
Introduced in:
5.0No fixed version published yet for topthink/framework (composer). Pin to a known-safe version or switch to an alternative.