Thinkphp · Thinkphp · CVE-2022-44289
**Name of the Vulnerable Software and Affected Versions**
Thinkphp versions 5.0.24 through 5.1.41
**Description**
The issue is caused by a code logic error that leads to a file upload getting shell access. This allows an attacker to potentially execute arbitrary code on the server.
**Recommendations**
For Thinkphp version 5.0.24, update to a version that fixes the code logic error.
For Thinkphp version 5.1.41, update to a version that fixes the code logic error.
As a temporary workaround, consider disabling the file upload feature until a patch is available.