Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Beicheng-Maker

#25294of 53,625
9.8Total CVSS
Vulnerabilities · 1
PT-2022-21693
9.8
2022-06-29
Thinkphp · Thinkphp · CVE-2022-33107
**Name of the Vulnerable Software and Affected Versions** ThinkPHP version 6.0.12 **Description** The issue is related to a deserialization vulnerability in the `vendorleagueflysystem-cached-adaptersrcStorageAbstractCache.php` component. This vulnerability allows attackers to execute arbitrary code via a crafted payload. **Recommendations** For ThinkPHP version 6.0.12, consider disabling the deserialization functionality in the `AbstractCache.php` component until a patch is available. Restrict access to the vulnerable component to minimize the risk of exploitation.