github.com
https://github.com/Stakcery/Web-Security/issues/1 CVE-2021-44892
HIGH
ThinkPHP Remote Code Execution (RCE) vulnerability
Record summary
CVE-2021-44892 has a selected CVSS score of 8.8 (high).
Description
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 15, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ThinkPHPBrowse thinkphp / ThinkPHP | VulnCheck | Version data not supplied | |
topthink/frameworkBrowse Packagist / topthink/framework | GitHub Advisory | Through 3.2.3 | affected |
References
3github.com
https://github.com/top-think/framework nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-44892