PT-2018-14057 · Thinkphp · Thinkphp

Ghost

·

Published

2018-09-26

·

Updated

2022-05-14

·

CVE-2018-17566

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ThinkPHP version 5.1.24
Description The issue allows for SQL injection when the delete function's WHERE condition value can be controlled by a user's request. This can potentially lead to unauthorized data access or modification.
Recommendations For ThinkPHP version 5.1.24, consider validating and sanitizing user input to prevent manipulation of the WHERE condition value in the delete function until a patch is available. Restrict access to sensitive data and ensure proper input handling to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17566
GHSA-75FM-52MM-Q5RM

Affected Products

Thinkphp