PT-2022-17318 · Unknown · Thinkphp Framework

CVE-2022-25481

·

Published

2022-03-20

·

Updated

2025-09-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ThinkPHP Framework version 5.0.24
Description The ThinkPHP Framework was discovered to be configured without the PATHINFO parameter, allowing attackers to access all system environment parameters from index.php. It is noted that this issue is disputed by a third party, as system environment exposure is an intended feature of the debugging mode.
Recommendations For ThinkPHP Framework version 5.0.24, consider configuring the PATHINFO parameter to prevent unauthorized access to system environment parameters. As a temporary workaround, consider disabling the debugging mode until a proper configuration can be implemented.

Exploit

Fix

Improper Access Control

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25481
GHSA-69WP-XWM7-69WM

Affected Products

Thinkphp Framework