CVE-2022-25481

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:thinkphp:thinkphp:5.0.24:*:*:*:*:*:*:*

History

23 Apr 2024, 08:15

Type Values Removed Values Added
Summary ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

Information

Published : 2022-03-21 00:15

Updated : 2024-08-03 05:16


NVD link : CVE-2022-25481

Mitre link : CVE-2022-25481


JSON object : View

Products Affected

thinkphp

  • thinkphp
CWE
CWE-668

Exposure of Resource to Wrong Sphere