CVE-2022-25481

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/03/2022
Last modified:
03/08/2024

Description

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thinkphp:thinkphp:5.0.24:*:*:*:*:*:*:*