VDB
Sign up
CRITICAL9.8

GHSA-vcm7-88jx-3r39

ThinkPHP SQL Injection vulnerability

Quick fix

GHSA-vcm7-88jx-3r39 — topthink/framework: upgrade to the fixed version with the command below.

composer require topthink/framework:^5.1.23

Details

ThinkPHP before 5.1.23 allows SQL Injection via the `public/index/index/test/index` query string.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/topthink/framework
Introduced in: 0Fixed in: 5.1.23
Fixcomposer require topthink/framework:^5.1.23

References