CVE-2022-25481 describes an information disclosure vulnerability in ThinkPHP Framework v5.0.24, stemming from its configuration without the PATHINFO parameter, which allows attackers to access system environment parameters via index.php. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low complexity to achieve high confidentiality impact. While a third party disputes this as an intended debugging feature, there are currently no known active exploits, Metasploit modules, or ExploitDB entries, though Nuclei templates exist for detection. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.24CPE matchmatch criteria | cpe:2.3:a:thinkphp:thinkphp:5.0.24:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.