ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| topthink/framework(Packagist) | 0 | N/A | N/A |
CVSS Metrics