PT-2022-17318 · Unknown · Thinkphp Framework
Published
2022-03-20
·
Updated
2025-09-03
·
CVE-2022-25481
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ThinkPHP Framework version 5.0.24
Description
The ThinkPHP Framework was discovered to be configured without the PATHINFO parameter, allowing attackers to access all system environment parameters from index.php. It is noted that this issue is disputed by a third party, as system environment exposure is an intended feature of the debugging mode.
Recommendations
For ThinkPHP Framework version 5.0.24, consider configuring the PATHINFO parameter to prevent unauthorized access to system environment parameters. As a temporary workaround, consider disabling the debugging mode until a proper configuration can be implemented.
Exploit
Fix
Improper Access Control
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Thinkphp Framework