Back

HIGH

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter

Published Mar 20, 2022

Description

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 20, 2022
Updated Aug 3, 2024
Reserved Feb 21, 2022
CISA Vulnrichment
Updated Apr 23, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-69WP-XWM7-69WM