PT-2022-21693 · Thinkphp+1 · Thinkphp+1

Beicheng-Maker

·

Published

2022-06-29

·

Updated

2022-07-08

·

CVE-2022-33107

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ThinkPHP version 6.0.12
Description The issue is related to a deserialization vulnerability in the vendorleagueflysystem-cached-adaptersrcStorageAbstractCache.php component. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
Recommendations For ThinkPHP version 6.0.12, consider disabling the deserialization functionality in the AbstractCache.php component until a patch is available. Restrict access to the vulnerable component to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-33107
GHSA-G377-X8RG-C9MF

Affected Products

Thinkphp
Flysystem-Cached-Adapter