Vulnerability Description
ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the attack URI.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Thinkphp | Thinkphp | 5.1.25 |
Related Weaknesses (CWE)
References
- https://www.kingkk.com/2018/10/Thinkphp-%E8%81%9A%E5%90%88%E6%9F%A5%E8%AF%A2%E6%ExploitThird Party Advisory
- https://www.kingkk.com/2018/10/Thinkphp-%E8%81%9A%E5%90%88%E6%9F%A5%E8%AF%A2%E6%ExploitThird Party Advisory
FAQ
What is CVE-2018-18530?
CVE-2018-18530 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ThinkPHP 5.1.25 has SQL Injection via the count parameter because the library/think/db/Query.php aggregate function mishandles the aggregate variable. NOTE: a backquote character is required in the at...
How severe is CVE-2018-18530?
CVE-2018-18530 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-18530?
Check the references section above for vendor advisories and patch information. Affected products include: Thinkphp Thinkphp.