A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.
References
Link | Resource |
---|---|
https://github.com/Stakcery/Web-Security/issues/1 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2022-02-10 09:15
Updated : 2022-02-23 10:05
NVD link : CVE-2021-44892
Mitre link : CVE-2021-44892
JSON object : View
CWE
Products Affected
thinkphp
- thinkphp