Enhancement: cves/2022/CVE-2022-25481.yaml by md
parent
4ea53749b4
commit
3c520c118c
|
@ -5,7 +5,7 @@ info:
|
||||||
author: caon
|
author: caon
|
||||||
severity: high
|
severity: high
|
||||||
description: |
|
description: |
|
||||||
ThinkPHP Framework v5.0.24 is susceptible to information disclosure. This version was discovered to be configured without the PATHINFO parameter. This can allow an attacker to access all system environment parameters from index.php, thereby possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.
|
ThinkPHP 5.0.24 is susceptible to information disclosure. This version was configured without the PATHINFO parameter. This can allow an attacker to access all system environment parameters from index.php, thereby possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.
|
||||||
reference:
|
reference:
|
||||||
- https://github.com/Lyther/VulnDiscover/blob/master/Web/ThinkPHP_InfoLeak.md
|
- https://github.com/Lyther/VulnDiscover/blob/master/Web/ThinkPHP_InfoLeak.md
|
||||||
- https://nvd.nist.gov/vuln/detail/CVE-2022-25481
|
- https://nvd.nist.gov/vuln/detail/CVE-2022-25481
|
||||||
|
|
Loading…
Reference in New Issue