Description
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0881 | A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges. |
Github GHSA |
GHSA-75jp-87w2-c6x2 | ThinkPHP Remote Code Execution (RCE) vulnerability |
References
| Link | Providers |
|---|---|
| https://github.com/Stakcery/Web-Security/issues/1 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T04:32:13.250Z
Reserved: 2021-12-13T00:00:00.000Z
Link: CVE-2021-44892
No data.
Status : Modified
Published: 2022-02-10T17:15:09.330
Modified: 2026-06-17T04:12:56.203
Link: CVE-2021-44892
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA