CVE-2024-34467

ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.
Configurations

No configuration.

History

21 Nov 2024, 09:18

Type Values Removed Values Added
References () https://github.com/top-think/framework/issues/2996 - () https://github.com/top-think/framework/issues/2996 -

16 Aug 2024, 19:35

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

12 Jun 2024, 15:15

Type Values Removed Values Added
Summary
  • (es) ThinkPHP 8.0.3 permite a atacantes remotos descubrir la cookie PHPSESSION porque think_exception.tpl (también conocido como código fuente de salida de error de depuración) proporciona esto en un mensaje de error para un URI manipulado en una solicitud GET.
Summary (en) ThinkPHP 8.0.3 allows remote attackers to discover the PHPSESSION cookie because think_exception.tpl (aka the debug error output source code) provides this in an error message for a crafted URI in a GET request. (en) ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

04 May 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-04 20:15

Updated : 2024-11-21 09:18


NVD link : CVE-2024-34467

Mitre link : CVE-2024-34467

CVE.ORG link : CVE-2024-34467


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')