{ "id": "CVE-2024-34467", "sourceIdentifier": "cve@mitre.org", "published": "2024-05-04T20:15:07.527", "lastModified": "2024-06-12T15:15:52.083", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl." }, { "lang": "es", "value": "ThinkPHP 8.0.3 permite a atacantes remotos descubrir la cookie PHPSESSION porque think_exception.tpl (tambi\u00e9n conocido como c\u00f3digo fuente de salida de error de depuraci\u00f3n) proporciona esto en un mensaje de error para un URI manipulado en una solicitud GET." } ], "metrics": {}, "references": [ { "url": "https://github.com/top-think/framework/issues/2996", "source": "cve@mitre.org" } ] }