PT-2022-17318 · Unknown · Thinkphp Framework

Published

2022-03-20

·

Updated

2025-09-03

·

CVE-2022-25481

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ThinkPHP Framework version 5.0.24
Description The ThinkPHP Framework was discovered to be configured without the PATHINFO parameter, allowing attackers to access all system environment parameters from index.php. It is noted that this issue is disputed by a third party, as system environment exposure is an intended feature of the debugging mode.
Recommendations For ThinkPHP Framework version 5.0.24, consider configuring the PATHINFO parameter to prevent unauthorized access to system environment parameters. As a temporary workaround, consider disabling the debugging mode until a proper configuration can be implemented.

Exploit

Fix

Improper Access Control

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2022-25481
GHSA-69WP-XWM7-69WM

Affected Products

Thinkphp Framework