CVE-2021-36567 is a critical deserialization vulnerability affecting ThinkPHP v6.0.8, specifically within the League\Flysystem\Cached\Storage\AbstractCache component. With a CVSS score of 9.8, it allows unauthenticated attackers to achieve complete compromise (confidentiality, integrity, availability) with low attack complexity over the network. While there are no known active exploits or public exploit frameworks like Metasploit, the vulnerability has garnered significant community discussion, indicating potential interest in developing exploits.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.8CPE matchmatch criteria | cpe:2.3:a:thinkphp:thinkphp:6.0.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.