VDB
Sign up
CRITICAL9.8

GHSA-q868-c4vw-qjx3

ThinkPHP5 SQL Injection vulnerability

Details

SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/topthink/framework
Introduced in: 5.0

No fixed version published yet for topthink/framework (composer). Pin to a known-safe version or switch to an alternative.

References