6.5
CVSSv2

CVE-2021-44892

Published: 10/02/2022 Updated: 23/02/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain server control privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thinkphp thinkphp 3.2.3