cve/2022/CVE-2022-25481.md
2024-06-18 02:51:15 +02:00

945 B

CVE-2022-25481

Description

** DISPUTED ** ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

POC

Reference

Github