Описание
ThinkPHP SQL injection vulnerability
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.
Пакеты
Наименование
topthink/framework
composer
Затронутые версииВерсия исправления
= 5.1.24
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
больше 7 лет назад
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.