Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Hzy030628

#24346of 53,633
9.8Total CVSS
Vulnerabilities · 1
PT-2022-24383
9.8
2022-09-15
Thinkphp · Thinkphp · CVE-2022-38352
**Name of the Vulnerable Software and Affected Versions** ThinkPHP version 6.0.13 **Description** The issue is related to a deserialization vulnerability via the `LeagueFlysystemCachedStoragePsr6Cache` component. This allows attackers to execute arbitrary code by using a crafted payload. **Recommendations** For ThinkPHP version 6.0.13, update to a version that fixes this issue to prevent exploitation. As a temporary workaround, consider disabling the `LeagueFlysystemCachedStoragePsr6Cache` component until a patch is available.