ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| topthink/framework(Packagist) | 8.0.0 | 8.0.4 | N/A |
| topthink/framework(Packagist) | 6.1.0 | 6.1.5 | N/A |
| topthink/framework(Packagist) | 0 | 6.0.17 | N/A |
CVSS Metrics