CVE-2022-25481

HIGH7.5EPSS 9.5%

Exposure of Resource to Wrong Sphere in ThinkPHP Framework

Published: 3/22/2022Modified: 7/3/2024

Description

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (3)